Bug in handling user certifications for specific contexts?
David Walker
dwalker at internet2.edu
Thu Sep 10 15:00:56 EDT 2015
It's not necessary (or desirable) to authenticate via password again.
The issue is that if the second SP is asking for Duo after the first
authenticated with Password, the second can't populate NameID in the
AuthnRequest to do "step up."
David
On 09/09/2015 03:23 PM, Tom Scavo wrote:
> On Wed, Sep 9, 2015 at 2:45 PM, David Walker <dwalker at internet2.edu> wrote:
>> I'll also point out that this is not really what I understand as "step
>> up," as the Password and Duo parts of the authentication may not be
>> performed for the same SP.
> Why does that matter? Why is it necessary to authenticate via password again?
>
> Tom
More information about the dev
mailing list