saml2 authentication contexts

Liam Hoekenga liamr at umich.edu
Wed Sep 25 16:48:41 EDT 2013


I'm looking at trying to expose additional authentication factors via
shibboleth.

Our SSO (cosign) can support pretty much anything.  Currently, our only
additional factor is based on RSA tokens (and is invoked in shib via
TimeSyncToken).

Are the intended uses for the additional SAML2 authentication contexts
defined anywhere?  Some of them are obvious (kerberos, ip, x509).  I'm not
sure I understand the difference between "Mobile /n/ Factor" contract and
unregistered, or the various flavors of Telephony.

When it comes right down to it, I guess we could customize the login
handler we're using to point specific authn contexts to whatever factors we
wanted, but I want to make sure we make appropriate choices.

Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130925/24f4246a/attachment.html 


More information about the users mailing list