<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
Thanks, Marvin. One final comment below...<br>
<br>
David<br>
<br>
<br>
<div>On 07/15/2015 01:06 PM, Marvin Addison wrote:<br>
... <br>
</div>
<blockquote
cite="mid:CACOs9MScQ7aACV2WVykH5QPq3XPPxVRk-TPA8T8DNbuD=QA3HQ@mail.gmail.com"
type="cite">
<div dir="ltr">
<div class="gmail_quote">
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div bgcolor="#FFFFFF" text="#000000"> What if Marvin's
Password login screen had a button to invoke X.509
authentication (and was the initial-authn)?</div>
</blockquote>
<div><br>
</div>
<div>That's actually a step backward. The
RequestedPrincipalContext machinery works great for driving
the user to the proper login process based on SP
requirements. That's not to say we can't do what you
suggested, but it would trade Duo functionality for a lesser
user experience. I'm hopeful we can get the functionality we
need without that tradeoff.</div>
</div>
</div>
</blockquote>
<br>
Oh well. I may mention it in the MCB-related documentation, though,
as a technique for sites that don't have a history of supporting
X.509 and other technologies that require little or no interaction.
They won't be as sensitive to the extra click, it becomes an
extension of the login screen they already see, and it seems easier
to implement. It also means that people with tokens never have to
type their user name and password, as they can select X.509 even
when the first SP doesn't request it.<br>
<br>
</body>
</html>