<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
{mso-style-priority:99;
mso-style-link:"Plain Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:18.0pt;
font-family:"Times New Roman","serif";}
span.PlainTextChar
{mso-style-name:"Plain Text Char";
mso-style-priority:99;
mso-style-link:"Plain Text";
font-family:"Times New Roman","serif";}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoPlainText"><span style="color:red">Shibboleth version: 3.2.0<o:p></o:p></span></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">Leonard Kroll<o:p></o:p></p>
<p class="MsoPlainText">UNIX / GIS Administrator<o:p></o:p></p>
<p class="MsoPlainText">Univ. Massachusetts Boston<o:p></o:p></p>
<p class="MsoPlainText">Leonard(dot)Kroll(at)umb.edu<o:p></o:p></p>
<p class="MsoPlainText">Phone: 617-287-5048<o:p></o:p></p>
<p class="MsoPlainText">fax: 617-287-5224<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">-----Original Message-----<br>
From: dev [mailto:dev-bounces@shibboleth.net] On Behalf Of Cantor, Scott<br>
Sent: Friday, October 16, 2015 1:09 PM<br>
To: Shib Dev<br>
Cc: Kicic Sakib; Edman Martin<br>
Subject: RE: OTP loginhandler</p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">> Is there any currently, or in near future, plans for a general OTP loginhandler?<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">Not in those exact terms. After 3.2.0 ships, we have to start working on a framework for running composite login flows. Assuming you mean OATH, that's a SFA method like Duo that has to be combined with a password step, and unlike Duo
it's not proprietary, so including a TOTP (or less likely HOTP) flow in the box would make sense.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">In practice, people don't use that sort of thing much. Convincing management to do for free what you can pay companies thousands of dollars to do sadly doesn't go the way you think it would.<o:p></o:p></p>
<p class="MsoPlainText"><o:p></o:p></p>
<p class="MsoPlainText">> If not them I would like some tips and tricks before I start developing one myself.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">I don't have any documentation on writing login flows. We have several already implemented, the SPNEGO flow is coming shortly, and there's always using External to implement the new logic in a servlet.<o:p></o:p></p>
<p class="MsoPlainText"><o:p></o:p></p>
<p class="MsoPlainText">> I am mostly interested in the loginhandler itself as the
<o:p></o:p></p>
<p class="MsoPlainText">> infrastructure behind it is relatively simple.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">Writing login flows is quite simple, and writing servlets using the External interface is simpler.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">-- Scott<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">--<o:p></o:p></p>
<p class="MsoPlainText">To unsubscribe from this list send an email to <a href="mailto:dev-unsubscribe@shibboleth.net">
<span style="color:windowtext;text-decoration:none">dev-unsubscribe@shibboleth.net</span></a><o:p></o:p></p>
</div>
</body>
</html>