Two factor authentication for shibboleth
Jared Hoffman
hoffmanj at kenyon.edu
Thu Nov 7 14:54:32 EST 2013
Scott,
I'd like to follow up on your reply to my inquiry in February on the
shibboleth user list. In February we were researching two factor shibboleth
options.
Now we've got a working trial of RSA two-factor with our VPN. We've got the
RSA Authentication Manager v8 and the Web Tier running as a test with our
Cisco VPN. We're trying to integrate RSA with shibboleth, but we're not
sure how to get our idp server to use RSA server to authenticate. RSA has
directed us to the Multi Factor Login Handler link below, but our technical
contacts have not been able to give any instruction or documentation beyond
this link.
https://www.google.com/url?q=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fdisplay%2FSHIB2%2FMulti%2BFactor%2BLogin%2BHandler&sa=D&sntz=1&usg=AFQjCNFpLnJgfHEhP2LBwjpi3VZYCDzgLQ
I understand that the Multi Factor Login Handler can check against multiple
factors, but don't have any instruction on how to tell shibboleth to see
RSA as an authenticator.
We have created a special shibboleth server just for this test. After we
test RSA we're going to look at duo so we have two vendors to compare.
We've looked for documentation but all we could find about two factor and
shibboleth was about duo security.
Thanks
Jared
On Fri, Feb 15, 2013 at 9:06 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 2/15/13 3:04 PM, "Jared Hoffman" <hoffmanj at kenyon.edu> wrote:
>
> >Has anyone had any experience integrating Shibboleth with two factor
> >authentication? The two vendors we are looking at, which claim they
> >can work with shibboleth, are RSA and Safe-Net. If you have any
> >experience with these and shibboleth, please let me know if you have
> >been able to make it work.
>
> I do SecurID via a JAAS login module I got from RSA. That part's basically
> nothing, it's the same as standard user/pass with Kerberos or LDAP. I
> wrapped it in more custom behavior to meet local needs, but that's not so
> much anything to do with two-factor.
>
> If you qualify your use case with more details about the impact of your
> two-factor approach relative to other methods you offer, and how it will
> be expected to interact with SPs, I can possibly provide more details.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
Jared Hoffman
System Manager
Kenyon College
hoffmanj at kenyon.edu
740.427.5948
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131107/ce88ea7f/attachment.html
More information about the users
mailing list