<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="overflow-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;">
<br id="lineBreakAtBeginningOfMessage">
<div><br>
<blockquote type="cite">
<div>On 31 Oct 2024, at 07:58, Mats Luspa <mats.luspa@irf.se> wrote:</div>
<br class="Apple-interchange-newline">
<div>
<div>
<p>Maybe I should rephrase the question.</p>
<p>I wonder if it's possible to use webauthn/MFA always even if the SP is not requiring that?</p>
</div>
</div>
</blockquote>
<div>Yes, if that is your only configured authentication flow. </div>
<br>
<blockquote type="cite">
<div>
<div>
<p>I was thinking this scenario:</p>
<p>If the user enters the SP the user gets the webauthn/MFA interface in passwordless flow. Enters the username and if the user does not have any passkey registered the user comes to username/password flow<b> if the SP is not requiring webauthn</b>, otherwise
 if<b> SP is requiring webauthn the resource is not accessible for the user</b>. If the user has passkey registered the login is proceeding in the usual way for passkey login.</p>
</div>
</div>
</blockquote>
<div><br>
</div>
<div>I see. You should be able to make that switch using the approach I mentioned (linked previously): if no FIDO credentials are registered, signal that to the MFA flow and then switch to the username/password flow. If the SP has signalled it wants MFA (I
 can not see an SP would specifically request a WebAuthn authentication method), but the user only uses a password, the IdP would not be able to satisfy the request, and so an error will be returned to the SP. If the SP had not requested MFA (or anything),
 and Password was sufficient, authentication will succeed. You could, of course, allow a fallback to username/password plus some other second factor (TOTP, and Duo are some options in the IdP), which could also satisfy a request for MFA from the SP. </div>
<div><br>
</div>
<div>Noting, you decide if you want to assert WebAuthn authentication as multi-factor. There are some warnings about that on this page: <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DAuthentication-Context-Classes-(Supported-Principals)">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DAuthentication-Context-Classes-(Supported-Principals)</a>.
 The authentication assurances of ‘passkeys’ are changing all the time, e.g. they can be synchronised between devices and, soon, exported and transferred between providers (Credential Exchange Protocol). Of course, you could restrict users to certain ‘strong’
 or trusted authenticators, e.g., hardware security keys—you can do that with the latest release candidate. </div>
<div><br>
</div>
<div><br>
</div>
<div>Phil</div>
<br>
<blockquote type="cite">
<div>
<div>
<p>/Regards Mats<br>
</p>
<div class="moz-cite-prefix">On 2024-10-30 10:48, Philip Smart wrote:<br>
</div>
<blockquote type="cite" cite="mid:107760A1-7811-4DC4-9C97-84C8E319C4D4@jisc.ac.uk">
<br id="lineBreakAtBeginningOfMessage">
<div><br>
<blockquote type="cite">
<div>On 30 Oct 2024, at 09:22, Mats Luspa via dev <a class="moz-txt-link-rfc2396E" href="mailto:dev@shibboleth.net">
<dev@shibboleth.net></a> wrote:</div>
<br class="Apple-interchange-newline">
<div>
<div>
<p>Hello again!</p>
<p>Is it possible to configure so the authentication process falls back to username/password if a passkey can't be discovered? Right now passkey is used only if the SP requires that. But most of the SP:s at least here don't require passkeys and hence username/password
 is used. I want the idp to decide that passkey should be used if possible (passkey is discovered).<br>
</p>
</div>
</div>
</blockquote>
<div>I guess this depends on what you mean by ‘discovered’. If you mean; does the user have a passkey registered with the IdP, then there are some options to signal ‘no passkeys’ to the MFA flow during authentication. You can then use MFA logic to decide what
 to do next. The docs need work, but this should be described in <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DSignalling-custom-events-when-the-user-has-no-registered-credentials" moz-do-not-send="true" class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DSignalling-custom-events-when-the-user-has-no-registered-credentials</a>.
 Please note the warning about enabling that feature (in the yellow box). </div>
<div><br>
</div>
<div>Or maybe you meant something else?</div>
<div><br>
</div>
<div>Phil</div>
<br>
<blockquote type="cite">
<div>
<div>
<p>/Regards Mats<br>
</p>
<div class="moz-cite-prefix">On 2024-10-30 07:24, Mats Luspa via dev wrote:<br>
</div>
<blockquote type="cite" cite="mid:6653933c-f518-42be-8fa6-5f532163661e@irf.se">
<p>You are absolutely correct. irfAuthorizedService is an ldap attribute not resolved. I have now made a scripted attribute that checks if irfAuthorizedService contains shibAdmin and it works now.</p>
<p>Thanks for pointing med to the right direction :)</p>
<p>/Regards Mats<br>
</p>
<div class="moz-cite-prefix">On 2024-10-29 21:35, Michael Grady via dev wrote:<br>
</div>
<blockquote type="cite" cite="mid:5DAF7CEE-21EC-4CCF-951A-8B2BDD7F140E@unicon.net">
<br>
<div><br>
<blockquote type="cite">
<div>On Oct 29, 2024, at 2:46 PM, Cantor, Scott via dev <a class="moz-txt-link-rfc2396E" href="mailto:dev@shibboleth.net" moz-do-not-send="true">
<dev@shibboleth.net></a> wrote:</div>
<br class="Apple-interchange-newline">
<div>
<div>
<blockquote type="cite" style="font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
I think it has to do with that irfAuthorizedService is a multi<br>
-value attribute.<br>
</blockquote>
<br style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
<span style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; float: none; display: inline !important;">It
 doesn't.</span></div>
</div>
</blockquote>
</div>
<div><br>
</div>
Yes the example I supplied (and that is from a working deployment), the attribute we used could have dozens and dozens of values, so multi-valued is most definitely not the issue.
<div><br>
<div>
<div>--<br>
Michael A. Grady<br>
IAM Architect, Unicon, Inc.</div>
<div><br>
</div>
<br class="Apple-interchange-newline">
</div>
<br>
</div>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset> </blockquote>
<pre class="moz-signature" cols="72">-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: <a class="moz-txt-link-abbreviated moz-txt-link-freetext" href="mailto:matsl@irf.se" moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext" href="https://www.irf.se/pgp/matsl" moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext" href="https://www.irf.se/vcard/mats.luspa" moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset> </blockquote>
<pre class="moz-signature" cols="72">-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: <a class="moz-txt-link-abbreviated moz-txt-link-freetext" href="mailto:matsl@irf.se" moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext" href="https://www.irf.se/pgp/matsl" moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext" href="https://www.irf.se/vcard/mats.luspa" moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
</div>
-- <br>
To unsubscribe from this list send an email to <a class="moz-txt-link-abbreviated" href="mailto:dev-unsubscribe@shibboleth.net">
dev-unsubscribe@shibboleth.net</a><br>
</div>
</blockquote>
</div>
<br>
<mc type="body"><font size="1"><font face="Corbel"><br>
<p>Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under company number. 05747339, VAT number GB 197 0632 86. Jisc’s registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
</p>
<p>Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 02881024, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
</p>
<p>Jisc Commercial Limited is a wholly owned Jisc subsidiary and a company limited by shares which is registered in England under company number 09316933, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
</p>
<p>For more details on how Jisc handles your data see our privacy notice here: <a class="moz-txt-link-freetext" href="https://www.jisc.ac.uk/website/privacy-notice">
https://www.jisc.ac.uk/website/privacy-notice</a></p>
</font></font></mc></blockquote>
<pre class="moz-signature" cols="72">-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: <a class="moz-txt-link-abbreviated" href="mailto:matsl@irf.se">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext" href="https://www.irf.se/pgp/matsl">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext" href="https://www.irf.se/vcard/mats.luspa">https://www.irf.se/vcard/mats.luspa</a></pre>
</div>
</div>
</blockquote>
</div>
<br>
</body>
</html>