<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Maybe I should rephrase the question.</p>
    <p>I wonder if it's possible to use webauthn/MFA always even if the
      SP is not requiring that?</p>
    <p>I was thinking this scenario:</p>
    <p>If the user enters the SP the user gets the webauthn/MFA
      interface in passwordless flow. Enters the username and if the
      user does not have any passkey registered the user comes to
      username/password flow<b> if the SP is not requiring webauthn</b>,
      otherwise if<b> SP is requiring webauthn the resource is not
        accessible for the user</b>. If the user has passkey registered
      the login is proceeding in the usual way for passkey login.</p>
    <p>/Regards Mats<br>
    </p>
    <div class="moz-cite-prefix">On 2024-10-30 10:48, Philip Smart
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:107760A1-7811-4DC4-9C97-84C8E319C4D4@jisc.ac.uk">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <br id="lineBreakAtBeginningOfMessage">
      <div><br>
        <blockquote type="cite">
          <div>On 30 Oct 2024, at 09:22, Mats Luspa via dev
            <a class="moz-txt-link-rfc2396E" href="mailto:dev@shibboleth.net"><dev@shibboleth.net></a> wrote:</div>
          <br class="Apple-interchange-newline">
          <div>
            <div>
              <p>Hello again!</p>
              <p>Is it possible to configure so the authentication
                process falls back to username/password if a passkey
                can't be discovered? Right now passkey is used only if
                the SP requires that. But most of the SP:s at least here
                don't require passkeys and hence username/password is
                used. I want the idp to decide that passkey should be
                used if possible (passkey is discovered).<br>
              </p>
            </div>
          </div>
        </blockquote>
        <div>I guess this depends on what you mean by ‘discovered’. If
          you mean; does the user have a passkey registered with the
          IdP, then there are some options to signal ‘no passkeys’ to
          the MFA flow during authentication. You can then use MFA logic
          to decide what to do next. The docs need work, but this should
          be described in <a
href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DSignalling-custom-events-when-the-user-has-no-registered-credentials"
            moz-do-not-send="true" class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DSignalling-custom-events-when-the-user-has-no-registered-credentials</a>.
          Please note the warning about enabling that feature (in the
          yellow box). </div>
        <div><br>
        </div>
        <div>Or maybe you meant something else?</div>
        <div><br>
        </div>
        <div>Phil</div>
        <br>
        <blockquote type="cite">
          <div>
            <div>
              <p>/Regards Mats<br>
              </p>
              <div class="moz-cite-prefix">On 2024-10-30 07:24, Mats
                Luspa via dev wrote:<br>
              </div>
              <blockquote type="cite"
                cite="mid:6653933c-f518-42be-8fa6-5f532163661e@irf.se">
                <p>You are absolutely correct. irfAuthorizedService is
                  an ldap attribute not resolved. I have now made a
                  scripted attribute that checks if irfAuthorizedService
                  contains shibAdmin and it works now.</p>
                <p>Thanks for pointing med to the right direction :)</p>
                <p>/Regards Mats<br>
                </p>
                <div class="moz-cite-prefix">On 2024-10-29 21:35,
                  Michael Grady via dev wrote:<br>
                </div>
                <blockquote type="cite"
cite="mid:5DAF7CEE-21EC-4CCF-951A-8B2BDD7F140E@unicon.net">
                  <br>
                  <div><br>
                    <blockquote type="cite">
                      <div>On Oct 29, 2024, at 2:46 PM, Cantor, Scott
                        via dev <a class="moz-txt-link-rfc2396E"
                          href="mailto:dev@shibboleth.net"
                          moz-do-not-send="true">
                          <dev@shibboleth.net></a> wrote:</div>
                      <br class="Apple-interchange-newline">
                      <div>
                        <div>
                          <blockquote type="cite"
style="font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
                            I think it has to do with that
                            irfAuthorizedService is a multi<br>
                            -value attribute.<br>
                          </blockquote>
                          <br
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
                          <span
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; float: none; display: inline !important;">It
                            doesn't.</span></div>
                      </div>
                    </blockquote>
                  </div>
                  <div><br>
                  </div>
                  Yes the example I supplied (and that is from a working
                  deployment), the attribute we used could have dozens
                  and dozens of values, so multi-valued is most
                  definitely not the issue.
                  <div><br>
                    <div>
                      <div>--<br>
                        Michael A. Grady<br>
                        IAM Architect, Unicon, Inc.</div>
                      <div><br>
                      </div>
                      <br class="Apple-interchange-newline">
                    </div>
                    <br>
                  </div>
                  <br>
                  <fieldset class="moz-mime-attachment-header"></fieldset>
                </blockquote>
                <pre class="moz-signature" cols="72">-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: <a
                class="moz-txt-link-abbreviated moz-txt-link-freetext"
                href="mailto:matsl@irf.se" moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext"
                href="https://www.irf.se/pgp/matsl"
                moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext"
                href="https://www.irf.se/vcard/mats.luspa"
                moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
                <br>
                <fieldset class="moz-mime-attachment-header"></fieldset>
              </blockquote>
              <pre class="moz-signature" cols="72">-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: <a
              class="moz-txt-link-abbreviated moz-txt-link-freetext"
              href="mailto:matsl@irf.se" moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext"
              href="https://www.irf.se/pgp/matsl" moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext"
              href="https://www.irf.se/vcard/mats.luspa"
              moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
            </div>
            -- <br>
            To unsubscribe from this list send an email to
            <a class="moz-txt-link-abbreviated" href="mailto:dev-unsubscribe@shibboleth.net">dev-unsubscribe@shibboleth.net</a><br>
          </div>
        </blockquote>
      </div>
      <br>
      <mc type="body"><font size="1"><font face="Corbel"><br>
            <p>Jisc is a registered charity (number 1149740) and a
              company limited by guarantee which is registered in
              England under company number. 05747339, VAT number GB 197
              0632 86. Jisc’s registered office is: 4 Portwall Lane,
              Bristol, BS1 6NB. T 0203 697 5800.<br>
              <br>
            </p>
            <p>Jisc Services Limited is a wholly owned Jisc subsidiary
              and a company limited by guarantee which is registered in
              England under company number 02881024, VAT number GB 197
              0632 86. The registered office is: 4 Portwall Lane,
              Bristol, BS1 6NB. T 0203 697 5800.<br>
              <br>
            </p>
            <p>Jisc Commercial Limited is a wholly owned Jisc subsidiary
              and a company limited by shares which is registered in
              England under company number 09316933, VAT number GB 197
              0632 86. The registered office is: 4 Portwall Lane,
              Bristol, BS1 6NB. T 0203 697 5800.<br>
              <br>
            </p>
            <p>For more details on how Jisc handles your data see our
              privacy notice here:
              <a class="moz-txt-link-freetext" href="https://www.jisc.ac.uk/website/privacy-notice">https://www.jisc.ac.uk/website/privacy-notice</a></p>
          </font></font>
      </mc></blockquote>
    <pre class="moz-signature" cols="72">-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: <a class="moz-txt-link-abbreviated" href="mailto:matsl@irf.se">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext" href="https://www.irf.se/pgp/matsl">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext" href="https://www.irf.se/vcard/mats.luspa">https://www.irf.se/vcard/mats.luspa</a></pre>
  </body>
</html>