attribute to indicate 2-factor authN for principal
David Bantz
dabantz at alaska.edu
Tue Nov 26 17:58:14 EST 2013
On Tue, 26 Nov 2013, at 13:28 , Douglas E. Engert <deengert at anl.gov> wrote:
> On 11/26/2013 3:51 PM, David Bantz wrote:
>> As a component of phased roll-out of 2-factor authentication, we’re envisioning enabling our users to opt in to use of two-factor authentication via our IdP.
>> That is, if “the paranoids” (as my CITO labeled us) set this flag, the IdP would consume an attribute from the enterprise directory and demand 2-factor authN
>> from anyone presenting my identifier. (This would not of course interfere with individual SPs requesting 2-factor or other assurance levels.)
>>
>> I am soliciting advice for the (LDAP) directory attribute to convey this information.
>
> If the attribute is only used by the IDP and its database, then the choice it is up to you, the SP will never see it.
> One problem, is the IDP presents a login page to the user before it knows who the user is.
> So users will ha e to be trained.
Yes, this is an attribute to be consumed (only) by the the IdP to “switch on” the additional request for second factor;
we’re not envisioning encoding the attribute and sending to the SP.
As you note, the initial default IdP login page remains unaware of any aspect of 2-factor authN; a subsequent page requesting
verification of the second factor will presented to (only) those users who opt in as indicated by the directory attribute.
David Bantz
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20131126/e88fd79b/attachment.bin
More information about the users
mailing list