<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>Yes, you are correct. In the registration process it works but
not in the authentication flow where you for those without
passkeys registrated go to authn/Password. <br>
</p>
<p>I tested with activationCondition (activate authn/Password only
if no passkey is regsistrated) according to below configuration
but it didn't work that either.</p>
<p><bean id="authn/Password"
parent="shibboleth.AuthenticationFlow"<br>
p:passiveAuthenticationSupported="true"<br>
p:forcedAuthenticationSupported="true"<br>
p:activationCondition-ref="checkWebAuthnAvailability"/></p>
<p><br>
</p>
<p><bean id="checkWebAuthnAvailability"
parent="shibboleth.Conditions.Scripted"
factory-method="inlineScript"><br>
<constructor-arg><br>
<value><br>
<![CDATA[<br>
var webauthnRegCtx =
profileRequestContext.getSubcontext(WebAuthnRegistrationContext.class);<br>
var result = webauthnRegCtx == null ||
!webauthnRegCtx.isWebAuthnAvailable();<br>
result;<br>
]]><br>
</value></p>
<p> </constructor-arg></p>
<p> </bean></p>
<p>Ok, I wait.</p>
<p>/Regards Mats<br>
</p>
<div class="moz-cite-prefix">Den 2024-11-03 kl. 10:41, skrev Philip
Smart:<br>
</div>
<blockquote type="cite"
cite="mid:3A5AE902-82C6-4E77-91A9-8BFD5CE1D85E@jisc.ac.uk">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<br id="lineBreakAtBeginningOfMessage">
<div><br>
<blockquote type="cite">
<div>On 3 Nov 2024, at 09:35, Philip Smart via dev
<a class="moz-txt-link-rfc2396E" href="mailto:dev@shibboleth.net"><dev@shibboleth.net></a> wrote:</div>
<br class="Apple-interchange-newline">
<div>
<div
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
<br class="Apple-interchange-newline">
<br>
<blockquote type="cite">
<div>On 2 Nov 2024, at 20:19, Mats Luspa <<a
href="mailto:mats.luspa@irf.se"
moz-do-not-send="true" class="moz-txt-link-freetext">mats.luspa@irf.se</a>>
wrote:</div>
<br class="Apple-interchange-newline">
<div>
<div>
<p>However I discovered the known issue that the
username (that has no passkey) collected in the
initial step is possible to alter in the
authn/Password step. That means that a user with
passkey can be degraded to username/password
authentication.</p>
<p>I've tested and it works to do that.</p>
<p>Is it possible to secure that the username in the
authn/Password step is the same as the username in
the initial step? The optimal would be to only
allow password input in the authn/Password step.</p>
</div>
</div>
</blockquote>
<div>Yes, this should be covered by the
‘AccessByCurrentUser’ policy as shown in <a
href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3879206915/WebAuthnRegistration#%5BinlineExtension%5DAccessPolicy-Configuration"
moz-do-not-send="true" class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3879206915/WebAuthnRegistration#%5BinlineExtension%5DAccessPolicy-Configuration</a>.
Let me know if that is not working (it is working for
me), as that is pretty fundamental. </div>
</div>
</div>
</blockquote>
<div><br>
</div>
Sorry, I might have answered this too quickly. I guess you mean
in the authentication flow, not for registration. Yeah, this is
why there is a warning about that. I will get back to you next
week.,</div>
<div><br>
</div>
<div>Phil<br>
<blockquote type="cite">
<div>
<div
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
<div><br>
</div>
<div>Phil</div>
<br>
<blockquote type="cite">
<div>
<div>
<p>/Regards Mats</p>
<div class="moz-cite-prefix">Den 2024-11-01 kl.
14:04, skrev Philip Smart:<br>
</div>
<blockquote type="cite"
cite="mid:B4B685A4-398E-46C2-A22D-D904A38380A1@jisc.ac.uk">
Excellent.
<div><br>
</div>
<div>Phil<br id="lineBreakAtBeginningOfMessage">
<div><br>
<blockquote type="cite">
<div>On 1 Nov 2024, at 12:01, Mats Luspa<span
class="Apple-converted-space"> </span><a
class="moz-txt-link-rfc2396E"
href="mailto:mats.luspa@irf.se"
moz-do-not-send="true"><mats.luspa@irf.se></a><span
class="Apple-converted-space"> </span>wrote:</div>
<br class="Apple-interchange-newline">
<div>
<div>
<p>Hello!</p>
<p>Thanks, it works now as I want it to
work with this configuration in
mfa-authn-config.xml (nearly
straightforward from documentation):</p>
<p><util:map
id="shibboleth.authn.MFA.TransitionMap"><br>
<entry key=""><br>
<bean
parent="shibboleth.authn.MFA.Transition"
p:nextFlowStrategy-ref="checkPasswordOrWebAuthn" /><br>
</entry><br>
<br>
<entry
key="authn/WebAuthn"><br>
<br>
<bean
parent="shibboleth.authn.MFA.Transition"><br>
<property
name="nextFlowStrategyMap"><br>
<map><br>
<entry
key="NoRegisteredWebAuthnCredentials"
value="authn/Password" /><br>
</map><br>
</property><br>
</bean><br>
</entry><br>
<br>
<!-- An implicit final rule
will return whatever the final flow
returns. --><br>
</util:map><br>
<br>
<bean
id="checkPasswordOrWebAuthn"
parent="shibboleth.ContextFunctions.Scripted"
factory-method="inlineScript"><br>
<constructor-arg><br>
<value><br>
<![CDATA[<br>
nextFlow =
"authn/WebAuthn";<br>
<br>
// Go straight to
second factor if we have to, or set up
for an attribute lookup first.<br>
webauthnRegCtx =
input.getSubcontext("net.shibboleth.idp.plugin.authn.webauthn.context.WebAuthnRegistrationContext");<br>
if (webauthnRegCtx !=
null) {<br>
if
(!webauthnRegCtx.isWebAuthnAvailable()){<br>
nextFlow =
"authn/Password";<br>
}<br>
}<span
class="Apple-converted-space"> </span><br>
nextFlow; // pass
control to second factor or end with
the first<br>
]]><br>
</value><br>
</constructor-arg><br>
</bean></p>
<p>and of course
NoRegisteredWebAuthnCredentials is
configured in authn-events-flow.xml.<br>
</p>
<p>Thanks for the advice!</p>
<p>/Regards Mats<br>
</p>
<div class="moz-cite-prefix">On
2024-10-31 12:22, Philip Smart wrote:<br>
</div>
<blockquote type="cite"
cite="mid:A299B515-507A-4047-A39E-7B0B884B778F@jisc.ac.uk">
<br id="lineBreakAtBeginningOfMessage">
<div><br>
<blockquote type="cite">
<div>On 31 Oct 2024, at 07:58,
Mats Luspa<span
class="Apple-converted-space"> </span><a
class="moz-txt-link-rfc2396E"
href="mailto:mats.luspa@irf.se" moz-do-not-send="true"><mats.luspa@irf.se></a><span
class="Apple-converted-space"> </span>wrote:</div>
<br
class="Apple-interchange-newline">
<div>
<div>
<p>Maybe I should rephrase the
question.</p>
<p>I wonder if it's possible
to use webauthn/MFA always
even if the SP is not
requiring that?</p>
</div>
</div>
</blockquote>
<div>Yes, if that is your only
configured authentication flow. </div>
<br>
<blockquote type="cite">
<div>
<div>
<p>I was thinking this
scenario:</p>
<p>If the user enters the SP
the user gets the
webauthn/MFA interface in
passwordless flow. Enters
the username and if the user
does not have any passkey
registered the user comes to
username/password flow<b><span
class="Apple-converted-space"> </span>if the SP is not requiring
webauthn</b>, otherwise if<b><span
class="Apple-converted-space"> </span>SP is requiring webauthn the
resource is not accessible
for the user</b>. If the
user has passkey registered
the login is proceeding in
the usual way for passkey
login.</p>
</div>
</div>
</blockquote>
<div><br>
</div>
<div>I see. You should be able to
make that switch using the
approach I mentioned (linked
previously): if no FIDO
credentials are registered, signal
that to the MFA flow and then
switch to the username/password
flow. If the SP has signalled it
wants MFA (I can not see an SP
would specifically request a
WebAuthn authentication method),
but the user only uses a password,
the IdP would not be able to
satisfy the request, and so an
error will be returned to the SP.
If the SP had not requested MFA
(or anything), and Password was
sufficient, authentication will
succeed. You could, of course,
allow a fallback to
username/password plus some other
second factor (TOTP, and Duo are
some options in the IdP), which
could also satisfy a request for
MFA from the SP. </div>
<div><br>
</div>
<div>Noting, you decide if you want
to assert WebAuthn authentication
as multi-factor. There are some
warnings about that on this page: <a
href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DAuthentication-Context-Classes-(Supported-Principals)"
moz-do-not-send="true"
class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DAuthentication-Context-Classes-(Supported-Principals)</a>.
The authentication assurances of
‘passkeys’ are changing all the
time, e.g. they can be
synchronised between devices and,
soon, exported and transferred
between providers (Credential
Exchange Protocol). Of course, you
could restrict users to certain
‘strong’ or trusted
authenticators, e.g., hardware
security keys—you can do that with
the latest release candidate. </div>
<div><br>
</div>
<div><br>
</div>
<div>Phil</div>
<br>
<blockquote type="cite">
<div>
<div>
<p>/Regards Mats<br>
</p>
<div class="moz-cite-prefix">On
2024-10-30 10:48, Philip
Smart wrote:<br>
</div>
<blockquote type="cite"
cite="mid:107760A1-7811-4DC4-9C97-84C8E319C4D4@jisc.ac.uk">
<br
id="lineBreakAtBeginningOfMessage">
<div><br>
<blockquote type="cite">
<div>On 30 Oct 2024, at
09:22, Mats Luspa via
dev<span
class="Apple-converted-space"> </span><a class="moz-txt-link-rfc2396E"
href="mailto:dev@shibboleth.net" moz-do-not-send="true"><dev@shibboleth.net></a><span
class="Apple-converted-space"> </span>wrote:</div>
<br
class="Apple-interchange-newline">
<div>
<div>
<p>Hello again!</p>
<p>Is it possible to
configure so the
authentication
process falls back
to
username/password
if a passkey can't
be discovered?
Right now passkey
is used only if
the SP requires
that. But most of
the SP:s at least
here don't require
passkeys and hence
username/password
is used. I want
the idp to decide
that passkey
should be used if
possible (passkey
is discovered).<br>
</p>
</div>
</div>
</blockquote>
<div>I guess this depends
on what you mean by
‘discovered’. If you
mean; does the user have
a passkey registered
with the IdP, then there
are some options to
signal ‘no passkeys’ to
the MFA flow during
authentication. You can
then use MFA logic to
decide what to do next.
The docs need work, but
this should be described
in <a
href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DSignalling-custom-events-when-the-user-has-no-registered-credentials"
moz-do-not-send="true"
class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3878256667/WebAuthnAuthentication#%5BinlineExtension%5DSignalling-custom-events-when-the-user-has-no-registered-credentials</a>.
Please note the warning
about enabling that
feature (in the yellow
box). </div>
<div><br>
</div>
<div>Or maybe you meant
something else?</div>
<div><br>
</div>
<div>Phil</div>
<br>
<blockquote type="cite">
<div>
<div>
<p>/Regards Mats<br>
</p>
<div
class="moz-cite-prefix">On 2024-10-30 07:24, Mats Luspa via dev wrote:<br>
</div>
<blockquote
type="cite"
cite="mid:6653933c-f518-42be-8fa6-5f532163661e@irf.se">
<p>You are
absolutely
correct.
irfAuthorizedService
is an ldap
attribute not
resolved. I have
now made a
scripted
attribute that
checks if
irfAuthorizedService
contains
shibAdmin and it
works now.</p>
<p>Thanks for
pointing med to
the right
direction :)</p>
<p>/Regards Mats<br>
</p>
<div
class="moz-cite-prefix">On 2024-10-29 21:35, Michael Grady via dev
wrote:<br>
</div>
<blockquote
type="cite"
cite="mid:5DAF7CEE-21EC-4CCF-951A-8B2BDD7F140E@unicon.net">
<br>
<div><br>
<blockquote
type="cite">
<div>On Oct
29, 2024, at
2:46 PM,
Cantor, Scott
via dev<span
class="Apple-converted-space"> </span><a class="moz-txt-link-rfc2396E"
href="mailto:dev@shibboleth.net" moz-do-not-send="true"><dev@shibboleth.net></a><span
class="Apple-converted-space"> </span>wrote:</div>
<br
class="Apple-interchange-newline">
<div>
<div>
<blockquote
type="cite"
style="font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
I think it has
to do with
that
irfAuthorizedService
is a multi<br>
-value
attribute.<br>
</blockquote>
<br
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
<span
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 20px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; float: none; display: inline !important;">It
doesn't.</span></div>
</div>
</blockquote>
</div>
<div><br>
</div>
Yes the example
I supplied (and
that is from a
working
deployment), the
attribute we
used could have
dozens and
dozens of
values, so
multi-valued is
most definitely
not the issue.
<div><br>
<div>
<div>--<br>
Michael A.
Grady<br>
IAM Architect,
Unicon, Inc.</div>
<div><br>
</div>
<br
class="Apple-interchange-newline">
</div>
<br>
</div>
<br>
<fieldset
class="moz-mime-attachment-header"></fieldset>
</blockquote>
<pre
class="moz-signature" cols="72">--
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik Fax: +46 (0)980 79 050
Swedish Institute of Space Physics email: <a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:matsl@irf.se" moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext"
href="https://www.irf.se/pgp/matsl" moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext"
href="https://www.irf.se/vcard/mats.luspa" moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
<br>
<fieldset
class="moz-mime-attachment-header"></fieldset>
</blockquote>
<pre
class="moz-signature" cols="72">--
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik Fax: +46 (0)980 79 050
Swedish Institute of Space Physics email: <a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:matsl@irf.se" moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext"
href="https://www.irf.se/pgp/matsl" moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext"
href="https://www.irf.se/vcard/mats.luspa" moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
</div>
--<span
class="Apple-converted-space"> </span><br>
To unsubscribe from
this list send an
email to<span
class="Apple-converted-space"> </span><a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:dev-unsubscribe@shibboleth.net" moz-do-not-send="true">dev-unsubscribe@shibboleth.net</a><br>
</div>
</blockquote>
</div>
<br>
<mc type="body"><font
size="1"><font
face="Corbel"><br>
<p>Jisc is a
registered charity
(number 1149740) and
a company limited by
guarantee which is
registered in
England under
company number.
05747339, VAT number
GB 197 0632 86.
Jisc’s registered
office is: 4
Portwall Lane,
Bristol, BS1 6NB. T
0203 697 5800.<br>
<br>
</p>
<p>Jisc Services
Limited is a wholly
owned Jisc
subsidiary and a
company limited by
guarantee which is
registered in
England under
company number
02881024, VAT number
GB 197 0632 86. The
registered office
is: 4 Portwall Lane,
Bristol, BS1 6NB. T
0203 697 5800.<br>
<br>
</p>
<p>Jisc Commercial
Limited is a wholly
owned Jisc
subsidiary and a
company limited by
shares which is
registered in
England under
company number
09316933, VAT number
GB 197 0632 86. The
registered office
is: 4 Portwall Lane,
Bristol, BS1 6NB. T
0203 697 5800.<br>
<br>
</p>
<p>For more details on
how Jisc handles
your data see our
privacy notice here:<span
class="Apple-converted-space"> </span><a class="moz-txt-link-freetext"
href="https://www.jisc.ac.uk/website/privacy-notice"
moz-do-not-send="true">https://www.jisc.ac.uk/website/privacy-notice</a></p>
</font></font></mc></blockquote>
<pre class="moz-signature"
cols="72">--
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik Fax: +46 (0)980 79 050
Swedish Institute of Space Physics email: <a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:matsl@irf.se"
moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext"
href="https://www.irf.se/pgp/matsl" moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext"
href="https://www.irf.se/vcard/mats.luspa" moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
</div>
</div>
</blockquote>
</div>
<br>
</blockquote>
<pre class="moz-signature" cols="72">--
--
Mats Luspa
Phone: +46 (0)980 79 022
Cellular phone: +46 (0)725813330
Institutet för rymdfysik Fax: +46 (0)980 79 050
Swedish Institute of Space Physics email: <a
class="moz-txt-link-abbreviated moz-txt-link-freetext"
href="mailto:matsl@irf.se"
moz-do-not-send="true">matsl@irf.se</a>
Visiting/Delivery address: Bengt Hultqvists väg 1, SE-981 92 Kiruna
Postal address: Box 812, SE-981 28 Kiruna
--
PGP Public Key: <a class="moz-txt-link-freetext"
href="https://www.irf.se/pgp/matsl"
moz-do-not-send="true">https://www.irf.se/pgp/matsl</a>
Digital vcard: <a class="moz-txt-link-freetext"
href="https://www.irf.se/vcard/mats.luspa" moz-do-not-send="true">https://www.irf.se/vcard/mats.luspa</a></pre>
</div>
</div>
</blockquote>
</div>
<br>
</div>
</blockquote>
</div>
</div>
</blockquote>
</div>
<br
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
<span
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; float: none; display: inline !important;">--<span
class="Apple-converted-space"> </span></span><br
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none;">
<span
style="caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; float: none; display: inline !important;">To
unsubscribe from this list send an email to<span
class="Apple-converted-space"> </span></span><a
href="mailto:dev-unsubscribe@shibboleth.net"
style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;"
moz-do-not-send="true" class="moz-txt-link-freetext">dev-unsubscribe@shibboleth.net</a></div>
</blockquote>
</div>
<br>
</blockquote>
</body>
</html>