specifying auth context on the IdP side?
Liam Hoekenga
liamr at umich.edu
Wed Oct 23 12:07:16 EDT 2013
The docs say that the default method is only used when another method
is not requested.
My concern is uncertainty re: whether we'd be specify the auth context
with this application's native SAML support. Specifically, what if we
can't specify the auth context (of our choice), but the app specifies
one on it's own? I guess that would be silly on the vendor's part..
but I've seen worse decisions.
Liam
On Wed, Oct 23, 2013 at 11:46 AM, Kevin P. Foote <kpfoote at iup.edu> wrote:
>
> On Wed, 23 Oct 2013, Liam Hoekenga wrote:
>
>> Acc'd to https://wiki.shibboleth.net/confluence/display/SHIB2/IdPRelyingParty,
>> it looks like we can state a preference for an auth context in the
>> replying party configuration:
>>
>> defaultAuthenticationMethod - the authentication method to use
>> for this relying party if it does not request a specific method
>>
>> Is it possible to /require/ a context? We're trying to integrate with
>> a system that speaks SAML natively, but doesn't allow us to specify
>> the auth context, but the users that we're deploying it for have a
>> business requirement of it requiring our 2FA (invoked by
>> TimeSyncToken).
>
> Yes, you can set the defaultAuthenticationMethod for that RP in your
> relying_party.xml
>
> Is that what you mean?
>
> ------
> thanks
> kevin.foote
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list