WebAuthn: Issue with Fido metadata?
Philip Smart
Philip.Smart at jisc.ac.uk
Wed Oct 30 09:48:27 UTC 2024
On 30 Oct 2024, at 09:22, Mats Luspa via dev <dev at shibboleth.net> wrote:
Hello again!
Is it possible to configure so the authentication process falls back to username/password if a passkey can't be discovered? Right now passkey is used only if the SP requires that. But most of the SP:s at least here don't require passkeys and hence username/password is used. I want the idp to decide that passkey should be used if possible (passkey is discovered).
I guess this depends on what you mean by ‘discovered’. If you mean; does the user have a passkey registered with the IdP, then there are some options to signal ‘no passkeys’ to the MFA flow during authentication. You can then use MFA logic to decide what to do next. The docs need work, but this should be described in https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DSignalling-custom-events-when-the-user-has-no-registered-credentials. Please note the warning about enabling that feature (in the yellow box).
Or maybe you meant something else?
Phil
/Regards Mats
On 2024-10-30 07:24, Mats Luspa via dev wrote:
You are absolutely correct. irfAuthorizedService is an ldap attribute not resolved. I have now made a scripted attribute that checks if irfAuthorizedService contains shibAdmin and it works now.
Thanks for pointing med to the right direction :)
/Regards Mats
On 2024-10-29 21:35, Michael Grady via dev wrote:
On Oct 29, 2024, at 2:46 PM, Cantor, Scott via dev <dev at shibboleth.net><mailto:dev at shibboleth.net> wrote:
I think it has to do with that irfAuthorizedService is a multi
-value attribute.
It doesn't.
Yes the example I supplied (and that is from a working deployment), the attribute we used could have dozens and dozens of values, so multi-valued is most definitely not the issue.
--
Michael A. Grady
IAM Architect, Unicon, Inc.
--
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik Fax: +46 (0)980 79 050
Swedish Institute of Space Physics email: matsl at irf.se<mailto:matsl at irf.se>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: https://www.irf.se/pgp/matsl
Digital vcard: https://www.irf.se/vcard/mats.luspa
--
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik Fax: +46 (0)980 79 050
Swedish Institute of Space Physics email: matsl at irf.se<mailto:matsl at irf.se>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: https://www.irf.se/pgp/matsl
Digital vcard: https://www.irf.se/vcard/mats.luspa
--
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under company number. 05747339, VAT number GB 197 0632 86. Jisc’s registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.
Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 02881024, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.
Jisc Commercial Limited is a wholly owned Jisc subsidiary and a company limited by shares which is registered in England under company number 09316933, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.
For more details on how Jisc handles your data see our privacy notice here: https://www.jisc.ac.uk/website/privacy-notice
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20241030/85e0201f/attachment-0001.htm>
More information about the dev
mailing list