authn/noop flow?

Scott Koranda skoranda at gmail.com
Fri Feb 3 15:25:32 EST 2017


Hi,

I don't want the IdP to lie, but I do want the MFA flow to be
able to decide using my strategy map that it should when it is
all done assert an MFA principal. A concrete example might be
the MFA strategy map looking at an IP address that indicates
that the user is on the VPN and the VPN requires MFA so we
want to assert MFA (after doing authn/Password of course to
know which user...).

For such a use case an "authn/noop" flow that can be
configured to assert the MFA principal would be handy.  It
would just do what authn/duo does in terms of the subject.

Can that be considered for the next release?

Or am I missing something fundamental?

Thanks,

Scott K


More information about the dev mailing list