saml2 authentication contexts
Liam Hoekenga
liamr at umich.edu
Wed Sep 25 16:53:24 EDT 2013
never mind. found it in
http://docs.oasis-open.org/security/saml/v2.0/saml-authn-context-2.0-os.pdf
Liam
On Wed, Sep 25, 2013 at 4:48 PM, Liam Hoekenga <liamr at umich.edu> wrote:
> I'm looking at trying to expose additional authentication factors via
> shibboleth.
>
> Our SSO (cosign) can support pretty much anything. Currently, our only
> additional factor is based on RSA tokens (and is invoked in shib via
> TimeSyncToken).
>
> Are the intended uses for the additional SAML2 authentication contexts
> defined anywhere? Some of them are obvious (kerberos, ip, x509). I'm not
> sure I understand the difference between "Mobile /n/ Factor" contract and
> unregistered, or the various flavors of Telephony.
>
> When it comes right down to it, I guess we could customize the login
> handler we're using to point specific authn contexts to whatever factors we
> wanted, but I want to make sure we make appropriate choices.
>
> Liam
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130925/19cc1c72/attachment.html
More information about the users
mailing list