Feedback on Multi-Context Broker Community Contribution

Tom Scavo trscavo at gmail.com
Mon Oct 21 18:18:13 EDT 2013


On Mon, Oct 21, 2013 at 5:05 PM, Wessel, Keith <kwessel at illinois.edu> wrote:
>
> The work that Duo did on their login handler is quite nice.

I consulted with Duo on that project a long time ago. They realized
early on that a Shib Login Handler was essential in the long run.

> I addition to
> the push authentication, it also supports token-based auth for users using
> the Mobile app with a OTP display.

That's correct.

> I haven’t looked into how this works,
> though, as I’ve neither taken the time to install it or look at the code.
> I’m sure others on the list could shed a little more light on this and
> possibly persuade you further.

I already did ;-)

Btw, the nice folks at Cirrus Identity recently integrated Duo with
simpleSAMLphp, so now we have multiple implementations. The
simpleSAMLphp implementation uses an updated Duo Auth API
(https://www.duosecurity.com/docs/authapi) which precludes the need
for sharing your phone number with Duo. You can also avoid sharing an
identifier for the user (as I mentioned before) if you're willing to
persist the opaque Duo identifier and use that instead.

Tom


More information about the users mailing list