Feedback on Multi-Context Broker Community Contribution
Tom Scavo
trscavo at gmail.com
Mon Oct 21 16:39:32 EDT 2013
On Mon, Oct 21, 2013 at 4:27 PM, Paul Hethmon
<paul.hethmon at clareitysecurity.com> wrote:
> I've been working on a project for InCommon to provide a Shibboleth
> Authentication Handler that implements ordered levels of authentication.
Great work, btw.
> So
> you could configure both a simple password and a two-factor system inside of
> Shibboleth and then let the SP request which one to use. So if Joe User
> first authenticates with password, a second SP (or even the first for that
> matter), could then send an authentication request that says to use
> two-factor authentication. The Multi-Context Broker (MCB) would then force
> the user to "upgrade" their authentication to two-factor to continue.
I call that "step-up authentication" but in any case we discussed that
briefly here just recently:
http://marc.info/?l=shibboleth-users&m=138168888328589&w=2
Are you saying that the MCB will recognize and act on a <Subject>
element in the <AuthnRequest> or are you signaling step-up
authentication in some other way?
Thanks,
Tom
More information about the users
mailing list