specifying auth context on the IdP side?

Liam Hoekenga liamr at umich.edu
Wed Oct 23 11:39:48 EDT 2013


Acc'd to https://wiki.shibboleth.net/confluence/display/SHIB2/IdPRelyingParty,
it looks like we can state a preference for an auth context in the
replying party configuration:

    defaultAuthenticationMethod - the authentication method to use
        for this relying party if it does not request a specific method

Is it possible to /require/ a context?  We're trying to integrate with
a system that speaks SAML natively, but doesn't allow us to specify
the auth context, but the users that we're deploying it for have a
business requirement of it requiring our 2FA (invoked by
TimeSyncToken).

Liam


More information about the users mailing list