<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Thanks, Marvin.  One final comment below...<br>
    <br>
    David<br>
    <br>
    <br>
    <div>On 07/15/2015 01:06 PM, Marvin Addison wrote:<br>
      ... <br>
    </div>
    <blockquote
cite="mid:CACOs9MScQ7aACV2WVykH5QPq3XPPxVRk-TPA8T8DNbuD=QA3HQ@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div class="gmail_quote"> 
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">
            <div bgcolor="#FFFFFF" text="#000000"> What if Marvin's
              Password login screen had a button to invoke X.509
              authentication (and was the initial-authn)?</div>
          </blockquote>
          <div><br>
          </div>
          <div>That's actually a step backward. The
            RequestedPrincipalContext machinery works great for driving
            the user to the proper login process based on SP
            requirements. That's not to say we can't do what you
            suggested, but it would trade Duo functionality for a lesser
            user experience. I'm hopeful we can get the functionality we
            need without that tradeoff.</div>
        </div>
      </div>
    </blockquote>
    <br>
    Oh well.  I may mention it in the MCB-related documentation, though,
    as a technique for sites that don't have a history of supporting
    X.509 and other technologies that require little or no interaction. 
    They won't be as sensitive to the extra click, it becomes an
    extension of the login screen they already see, and it seems easier
    to implement.  It also means that people with tokens never have to
    type their user name and password, as they can select X.509 even
    when the first SP doesn't request it.<br>
    <br>
  </body>
</html>