Bug in handling user certifications for specific contexts?

David Walker dwalker at internet2.edu
Thu Sep 10 15:00:56 EDT 2015


It's not necessary (or desirable) to authenticate via password again. 
The issue is that if the second SP is asking for Duo after the first
authenticated with Password, the second can't populate NameID in the
AuthnRequest to do "step up."

David


On 09/09/2015 03:23 PM, Tom Scavo wrote:
> On Wed, Sep 9, 2015 at 2:45 PM, David Walker <dwalker at internet2.edu> wrote:
>> I'll also point out that this is not really what I understand as "step
>> up," as the Password and Duo parts of the authentication may not be
>> performed for the same SP.
> Why does that matter? Why is it necessary to authenticate via password again?
>
> Tom



More information about the dev mailing list