Federation and Multifactor Authentication
Castellow, Robert
castellr at musc.edu
Wed Apr 25 17:06:37 BST 2012
Hello:
I am researching using multifactor authentication using the MFA Login handler in Shibboleth, and I'm trying to understand the workflow for federated identities that use services within our organization.
If a user authenticates within another organization and they have an active Shibboleth session and try to visit a service provider within our organization, is it implied that we continue to trust our federated partners but are adding an extra level of security in authenticating our own users through MFA on our local IdP? It seems that even though we are requiring a certain level of authentication within our own accounts, that we may or may not receive the same level of security from our partners. Is this correct?
Thanks in advance for any clarification on this topic.
Rob Castellow
Systems Engineer
IAS, OCIO
Medical University of South Carolina
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120425/eccbf10f/attachment.html
More information about the users
mailing list