<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Yes, you are correct. In the registration process it works but
      not in the authentication flow where you for those without
      passkeys registrated go to authn/Password. <br>
    </p>
    <p>I tested with activationCondition (activate authn/Password only
      if no passkey is regsistrated) according to below configuration
      but it didn't work that either.</p>
    <p><bean id="authn/Password"
      parent="shibboleth.AuthenticationFlow"<br>
                      p:passiveAuthenticationSupported="true"<br>
                      p:forcedAuthenticationSupported="true"<br>
                     
      p:activationCondition-ref="checkWebAuthnAvailability"/></p>
    <p><br>
    </p>
    <p><bean id="checkWebAuthnAvailability"
      parent="shibboleth.Conditions.Scripted"
      factory-method="inlineScript"><br>
                          <constructor-arg><br>
                                          <value><br>
                                                             
      <![CDATA[<br>
                                                                     
      var webauthnRegCtx =
      profileRequestContext.getSubcontext(WebAuthnRegistrationContext.class);<br>
                                                                     
      var result = webauthnRegCtx == null ||
      !webauthnRegCtx.isWebAuthnAvailable();<br>
                                                                     
      result;<br>
                                                                     
      ]]><br>
                                                          </value></p>
    <p>                       </constructor-arg></p>
    <p> </bean></p>
    <p>Ok, I wait.</p>
    <p>/Regards Mats<br>
    </p>
    <div class="moz-cite-prefix">Den 2024-11-03 kl. 10:41, skrev Philip
      Smart:<br>
    </div>
    <blockquote type="cite"
      cite="mid:3A5AE902-82C6-4E77-91A9-8BFD5CE1D85E@jisc.ac.uk">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <br id="lineBreakAtBeginningOfMessage">
      <div><br>
        <blockquote type="cite">
          <div>On 3 Nov 2024, at 09:35, Philip Smart via dev
            <a class="moz-txt-link-rfc2396E" href="mailto:dev@shibboleth.net"><dev@shibboleth.net></a> wrote:</div>
          <br class="Apple-interchange-newline">
          <div>
            <div
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
              <br class="Apple-interchange-newline">
              <br>
              <blockquote type="cite">
                <div>On 2 Nov 2024, at 20:19, Mats Luspa <<a
                    href="mailto:mats.luspa@irf.se"
                    moz-do-not-send="true" class="moz-txt-link-freetext">mats.luspa@irf.se</a>>
                  wrote:</div>
                <br class="Apple-interchange-newline">
                <div>
                  <div>
                    <p>However I discovered the known issue that the
                      username (that has no passkey) collected in the
                      initial step is possible to alter in the
                      authn/Password step. That means that a user with
                      passkey can be degraded to username/password
                      authentication.</p>
                    <p>I've tested and it works to do that.</p>
                    <p>Is it possible to secure that the username in the
                      authn/Password step is the same as the username in
                      the initial step? The optimal would be to only
                      allow password input in the authn/Password step.</p>
                  </div>
                </div>
              </blockquote>
              <div>Yes, this should be covered by the
                ‘AccessByCurrentUser’ policy as shown in <a
href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3879206915/WebAuthnRegistration#%5BinlineExtension%5DAccessPolicy-Configuration"
                  moz-do-not-send="true" class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3879206915/WebAuthnRegistration#%5BinlineExtension%5DAccessPolicy-Configuration</a>.
                Let me know if that is not working (it is working for
                me), as that is pretty fundamental. </div>
            </div>
          </div>
        </blockquote>
        <div><br>
        </div>
        Sorry, I might have answered this too quickly. I guess you mean
        in the authentication flow, not for registration. Yeah, this is
        why there is a warning about that. I will get back to you next
        week.,</div>
      <div><br>
      </div>
      <div>Phil<br>
        <blockquote type="cite">
          <div>
            <div
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
              <div><br>
              </div>
              <div>Phil</div>
              <br>
              <blockquote type="cite">
                <div>
                  <div>
                    <p>/Regards Mats</p>
                    <div class="moz-cite-prefix">Den 2024-11-01 kl.
                      14:04, skrev Philip Smart:<br>
                    </div>
                    <blockquote type="cite"
cite="mid:B4B685A4-398E-46C2-A22D-D904A38380A1@jisc.ac.uk">
                      Excellent. 
                      <div><br>
                      </div>
                      <div>Phil<br id="lineBreakAtBeginningOfMessage">
                        <div><br>
                          <blockquote type="cite">
                            <div>On 1 Nov 2024, at 12:01, Mats Luspa<span
                                class="Apple-converted-space"> </span><a
                                class="moz-txt-link-rfc2396E"
                                href="mailto:mats.luspa@irf.se"
                                moz-do-not-send="true"><mats.luspa@irf.se></a><span
                                class="Apple-converted-space"> </span>wrote:</div>
                            <br class="Apple-interchange-newline">
                            <div>
                              <div>
                                <p>Hello!</p>
                                <p>Thanks, it works now as I want it to
                                  work with this configuration in
                                  mfa-authn-config.xml (nearly
                                  straightforward from documentation):</p>
                                <p><util:map
                                  id="shibboleth.authn.MFA.TransitionMap"><br>
                                                  <entry key=""><br>
                                                          <bean
                                  parent="shibboleth.authn.MFA.Transition"
p:nextFlowStrategy-ref="checkPasswordOrWebAuthn" /><br>
                                                  </entry><br>
                                  <br>
                                                  <entry
                                  key="authn/WebAuthn"><br>
                                  <br>
                                                          <bean
                                  parent="shibboleth.authn.MFA.Transition"><br>
                                                                 
                                  <property
                                  name="nextFlowStrategyMap"><br>
                                        <map><br>
                                                <entry
                                  key="NoRegisteredWebAuthnCredentials"
                                  value="authn/Password" /><br>
                                        </map><br>
                                                                 
                                  </property><br>
                                                          </bean><br>
                                                  </entry><br>
                                  <br>
                                          <!-- An implicit final rule
                                  will return whatever the final flow
                                  returns. --><br>
                                  </util:map><br>
                                  <br>
                                      <bean
                                  id="checkPasswordOrWebAuthn"
                                  parent="shibboleth.ContextFunctions.Scripted"
                                  factory-method="inlineScript"><br>
                                          <constructor-arg><br>
                                              <value><br>
                                              <![CDATA[<br>
                                                  nextFlow =
                                  "authn/WebAuthn";<br>
                                  <br>
                                                  // Go straight to
                                  second factor if we have to, or set up
                                  for an attribute lookup first.<br>
                                                  webauthnRegCtx =
input.getSubcontext("net.shibboleth.idp.plugin.authn.webauthn.context.WebAuthnRegistrationContext");<br>
                                                  if (webauthnRegCtx !=
                                  null) {<br>
                                                          if
                                  (!webauthnRegCtx.isWebAuthnAvailable()){<br>
                                                              nextFlow =
                                  "authn/Password";<br>
                                                          }<br>
                                                  }<span
                                    class="Apple-converted-space"> </span><br>
                                                  nextFlow;   // pass
                                  control to second factor or end with
                                  the first<br>
                                              ]]><br>
                                              </value><br>
                                          </constructor-arg><br>
                                      </bean></p>
                                <p>and of course
                                  NoRegisteredWebAuthnCredentials is
                                  configured in authn-events-flow.xml.<br>
                                </p>
                                <p>Thanks for the advice!</p>
                                <p>/Regards Mats<br>
                                </p>
                                <div class="moz-cite-prefix">On
                                  2024-10-31 12:22, Philip Smart wrote:<br>
                                </div>
                                <blockquote type="cite"
cite="mid:A299B515-507A-4047-A39E-7B0B884B778F@jisc.ac.uk">
                                  <br id="lineBreakAtBeginningOfMessage">
                                  <div><br>
                                    <blockquote type="cite">
                                      <div>On 31 Oct 2024, at 07:58,
                                        Mats Luspa<span
                                          class="Apple-converted-space"> </span><a
                                          class="moz-txt-link-rfc2396E"
href="mailto:mats.luspa@irf.se" moz-do-not-send="true"><mats.luspa@irf.se></a><span
                                          class="Apple-converted-space"> </span>wrote:</div>
                                      <br
class="Apple-interchange-newline">
                                      <div>
                                        <div>
                                          <p>Maybe I should rephrase the
                                            question.</p>
                                          <p>I wonder if it's possible
                                            to use webauthn/MFA always
                                            even if the SP is not
                                            requiring that?</p>
                                        </div>
                                      </div>
                                    </blockquote>
                                    <div>Yes, if that is your only
                                      configured authentication flow. </div>
                                    <br>
                                    <blockquote type="cite">
                                      <div>
                                        <div>
                                          <p>I was thinking this
                                            scenario:</p>
                                          <p>If the user enters the SP
                                            the user gets the
                                            webauthn/MFA interface in
                                            passwordless flow. Enters
                                            the username and if the user
                                            does not have any passkey
                                            registered the user comes to
                                            username/password flow<b><span
class="Apple-converted-space"> </span>if the SP is not requiring
                                              webauthn</b>, otherwise if<b><span
class="Apple-converted-space"> </span>SP is requiring webauthn the
                                              resource is not accessible
                                              for the user</b>. If the
                                            user has passkey registered
                                            the login is proceeding in
                                            the usual way for passkey
                                            login.</p>
                                        </div>
                                      </div>
                                    </blockquote>
                                    <div><br>
                                    </div>
                                    <div>I see. You should be able to
                                      make that switch using the
                                      approach I mentioned (linked
                                      previously): if no FIDO
                                      credentials are registered, signal
                                      that to the MFA flow and then
                                      switch to the username/password
                                      flow. If the SP has signalled it
                                      wants MFA (I can not see an SP
                                      would specifically request a
                                      WebAuthn authentication method),
                                      but the user only uses a password,
                                      the IdP would not be able to
                                      satisfy the request, and so an
                                      error will be returned to the SP.
                                      If the SP had not requested MFA
                                      (or anything), and Password was
                                      sufficient, authentication will
                                      succeed. You could, of course,
                                      allow a fallback to
                                      username/password plus some other
                                      second factor (TOTP, and Duo are
                                      some options in the IdP), which
                                      could also satisfy a request for
                                      MFA from the SP. </div>
                                    <div><br>
                                    </div>
                                    <div>Noting, you decide if you want
                                      to assert WebAuthn authentication
                                      as multi-factor. There are some
                                      warnings about that on this page: <a
href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DAuthentication-Context-Classes-(Supported-Principals)"
                                        moz-do-not-send="true"
                                        class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DAuthentication-Context-Classes-(Supported-Principals)</a>.
                                      The authentication assurances of
                                      ‘passkeys’ are changing all the
                                      time, e.g. they can be
                                      synchronised between devices and,
                                      soon, exported and transferred
                                      between providers (Credential
                                      Exchange Protocol). Of course, you
                                      could restrict users to certain
                                      ‘strong’ or trusted
                                      authenticators, e.g., hardware
                                      security keys—you can do that with
                                      the latest release candidate. </div>
                                    <div><br>
                                    </div>
                                    <div><br>
                                    </div>
                                    <div>Phil</div>
                                    <br>
                                    <blockquote type="cite">
                                      <div>
                                        <div>
                                          <p>/Regards Mats<br>
                                          </p>
                                          <div class="moz-cite-prefix">On
                                            2024-10-30 10:48, Philip
                                            Smart wrote:<br>
                                          </div>
                                          <blockquote type="cite"
cite="mid:107760A1-7811-4DC4-9C97-84C8E319C4D4@jisc.ac.uk">
                                            <br
id="lineBreakAtBeginningOfMessage">
                                            <div><br>
                                              <blockquote type="cite">
                                                <div>On 30 Oct 2024, at
                                                  09:22, Mats Luspa via
                                                  dev<span
class="Apple-converted-space"> </span><a class="moz-txt-link-rfc2396E"
href="mailto:dev@shibboleth.net" moz-do-not-send="true"><dev@shibboleth.net></a><span
class="Apple-converted-space"> </span>wrote:</div>
                                                <br
class="Apple-interchange-newline">
                                                <div>
                                                  <div>
                                                    <p>Hello again!</p>
                                                    <p>Is it possible to
                                                      configure so the
                                                      authentication
                                                      process falls back
                                                      to
                                                      username/password
                                                      if a passkey can't
                                                      be discovered?
                                                      Right now passkey
                                                      is used only if
                                                      the SP requires
                                                      that. But most of
                                                      the SP:s at least
                                                      here don't require
                                                      passkeys and hence
                                                      username/password
                                                      is used. I want
                                                      the idp to decide
                                                      that passkey
                                                      should be used if
                                                      possible (passkey
                                                      is discovered).<br>
                                                    </p>
                                                  </div>
                                                </div>
                                              </blockquote>
                                              <div>I guess this depends
                                                on what you mean by
                                                ‘discovered’. If you
                                                mean; does the user have
                                                a passkey registered
                                                with the IdP, then there
                                                are some options to
                                                signal ‘no passkeys’ to
                                                the MFA flow during
                                                authentication. You can
                                                then use MFA logic to
                                                decide what to do next.
                                                The docs need work, but
                                                this should be described
                                                in <a
href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DSignalling-custom-events-when-the-user-has-no-registered-credentials"
                                                  moz-do-not-send="true"
class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DSignalling-custom-events-when-the-user-has-no-registered-credentials</a>.
                                                Please note the warning
                                                about enabling that
                                                feature (in the yellow
                                                box). </div>
                                              <div><br>
                                              </div>
                                              <div>Or maybe you meant
                                                something else?</div>
                                              <div><br>
                                              </div>
                                              <div>Phil</div>
                                              <br>
                                              <blockquote type="cite">
                                                <div>
                                                  <div>
                                                    <p>/Regards Mats<br>
                                                    </p>
                                                    <div
class="moz-cite-prefix">On 2024-10-30 07:24, Mats Luspa via dev wrote:<br>
                                                    </div>
                                                    <blockquote
                                                      type="cite"
cite="mid:6653933c-f518-42be-8fa6-5f532163661e@irf.se">
                                                      <p>You are
                                                        absolutely
                                                        correct.
                                                        irfAuthorizedService
                                                        is an ldap
                                                        attribute not
                                                        resolved. I have
                                                        now made a
                                                        scripted
                                                        attribute that
                                                        checks if
                                                        irfAuthorizedService
                                                        contains
                                                        shibAdmin and it
                                                        works now.</p>
                                                      <p>Thanks for
                                                        pointing med to
                                                        the right
                                                        direction :)</p>
                                                      <p>/Regards Mats<br>
                                                      </p>
                                                      <div
class="moz-cite-prefix">On 2024-10-29 21:35, Michael Grady via dev
                                                        wrote:<br>
                                                      </div>
                                                      <blockquote
                                                        type="cite"
cite="mid:5DAF7CEE-21EC-4CCF-951A-8B2BDD7F140E@unicon.net">
                                                        <br>
                                                        <div><br>
                                                          <blockquote
                                                          type="cite">
                                                          <div>On Oct
                                                          29, 2024, at
                                                          2:46 PM,
                                                          Cantor, Scott
                                                          via dev<span
class="Apple-converted-space"> </span><a class="moz-txt-link-rfc2396E"
href="mailto:dev@shibboleth.net" moz-do-not-send="true"><dev@shibboleth.net></a><span
class="Apple-converted-space"> </span>wrote:</div>
                                                          <br
class="Apple-interchange-newline">
                                                          <div>
                                                          <div>
                                                          <blockquote
                                                          type="cite"
style="font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
                                                          I think it has
                                                          to do with
                                                          that
                                                          irfAuthorizedService
                                                          is a multi<br>
                                                          -value
                                                          attribute.<br>
                                                          </blockquote>
                                                          <br
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
                                                          <span
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; float: none; display: inline !important;">It
                                                          doesn't.</span></div>
                                                          </div>
                                                          </blockquote>
                                                        </div>
                                                        <div><br>
                                                        </div>
                                                        Yes the example
                                                        I supplied (and
                                                        that is from a
                                                        working
                                                        deployment), the
                                                        attribute we
                                                        used could have
                                                        dozens and
                                                        dozens of
                                                        values, so
                                                        multi-valued is
                                                        most definitely
                                                        not the issue.
                                                        <div><br>
                                                          <div>
                                                          <div>--<br>
                                                          Michael A.
                                                          Grady<br>
                                                          IAM Architect,
                                                          Unicon, Inc.</div>
                                                          <div><br>
                                                          </div>
                                                          <br
class="Apple-interchange-newline">
                                                          </div>
                                                          <br>
                                                        </div>
                                                        <br>
                                                        <fieldset
class="moz-mime-attachment-header"></fieldset>
                                                      </blockquote>
                                                      <pre
class="moz-signature" cols="72">-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: <a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:matsl@irf.se" moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext"
href="https://www.irf.se/pgp/matsl" moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext"
href="https://www.irf.se/vcard/mats.luspa" moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
                                                      <br>
                                                      <fieldset
class="moz-mime-attachment-header"></fieldset>
                                                    </blockquote>
                                                    <pre
class="moz-signature" cols="72">-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: <a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:matsl@irf.se" moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext"
href="https://www.irf.se/pgp/matsl" moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext"
href="https://www.irf.se/vcard/mats.luspa" moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
                                                  </div>
                                                  --<span
class="Apple-converted-space"> </span><br>
                                                  To unsubscribe from
                                                  this list send an
                                                  email to<span
class="Apple-converted-space"> </span><a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:dev-unsubscribe@shibboleth.net" moz-do-not-send="true">dev-unsubscribe@shibboleth.net</a><br>
                                                </div>
                                              </blockquote>
                                            </div>
                                            <br>
                                            <mc type="body"><font
                                                size="1"><font
                                                  face="Corbel"><br>
                                                  <p>Jisc is a
                                                    registered charity
                                                    (number 1149740) and
                                                    a company limited by
                                                    guarantee which is
                                                    registered in
                                                    England under
                                                    company number.
                                                    05747339, VAT number
                                                    GB 197 0632 86.
                                                    Jisc’s registered
                                                    office is: 4
                                                    Portwall Lane,
                                                    Bristol, BS1 6NB. T
                                                    0203 697 5800.<br>
                                                    <br>
                                                  </p>
                                                  <p>Jisc Services
                                                    Limited is a wholly
                                                    owned Jisc
                                                    subsidiary and a
                                                    company limited by
                                                    guarantee which is
                                                    registered in
                                                    England under
                                                    company number
                                                    02881024, VAT number
                                                    GB 197 0632 86. The
                                                    registered office
                                                    is: 4 Portwall Lane,
                                                    Bristol, BS1 6NB. T
                                                    0203 697 5800.<br>
                                                    <br>
                                                  </p>
                                                  <p>Jisc Commercial
                                                    Limited is a wholly
                                                    owned Jisc
                                                    subsidiary and a
                                                    company limited by
                                                    shares which is
                                                    registered in
                                                    England under
                                                    company number
                                                    09316933, VAT number
                                                    GB 197 0632 86. The
                                                    registered office
                                                    is: 4 Portwall Lane,
                                                    Bristol, BS1 6NB. T
                                                    0203 697 5800.<br>
                                                    <br>
                                                  </p>
                                                  <p>For more details on
                                                    how Jisc handles
                                                    your data see our
                                                    privacy notice here:<span
class="Apple-converted-space"> </span><a class="moz-txt-link-freetext"
href="https://www.jisc.ac.uk/website/privacy-notice"
moz-do-not-send="true">https://www.jisc.ac.uk/website/privacy-notice</a></p>
                                                </font></font></mc></blockquote>
                                          <pre class="moz-signature"
                                          cols="72">-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: <a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
                                          href="mailto:matsl@irf.se"
                                          moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext"
href="https://www.irf.se/pgp/matsl" moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext"
href="https://www.irf.se/vcard/mats.luspa" moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
                                        </div>
                                      </div>
                                    </blockquote>
                                  </div>
                                  <br>
                                </blockquote>
                                <pre class="moz-signature" cols="72">-- 
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik               Fax: +46 (0)980 79 050
Swedish Institute of Space Physics      email: <a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
                                href="mailto:matsl@irf.se"
                                moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext"
                                href="https://www.irf.se/pgp/matsl"
                                moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext"
href="https://www.irf.se/vcard/mats.luspa" moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
                              </div>
                            </div>
                          </blockquote>
                        </div>
                        <br>
                      </div>
                    </blockquote>
                  </div>
                </div>
              </blockquote>
            </div>
            <br
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
            <span
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; float: none; display: inline !important;">--<span
                class="Apple-converted-space"> </span></span><br
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
            <span
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; float: none; display: inline !important;">To
              unsubscribe from this list send an email to<span
                class="Apple-converted-space"> </span></span><a
              href="mailto:dev-unsubscribe@shibboleth.net"
style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;"
              moz-do-not-send="true" class="moz-txt-link-freetext">dev-unsubscribe@shibboleth.net</a></div>
        </blockquote>
      </div>
      <br>
    </blockquote>
  </body>
</html>