<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">So an SP can request MFA but if you set the initial authn flow property to Password, it will always run Password if there's no session, regardless of what it eventually may have to run for the SP's needs.<br></blockquote><div><br></div><div>At face value that's a deal breaker. We rely on the requested principal mechanism to trigger X.509 auth as a part of our InCommon Silver compliance. Thus password auth is the default mech unless the SP requests silver; in that case password auth SHOULD NOT occur.</div><div><br></div><div>M<a href="mailto:dev-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div></div></div>