saml2 authentication contexts

Tom Scavo trscavo at gmail.com
Thu Sep 26 13:38:43 EDT 2013


On Thu, Sep 26, 2013 at 12:53 PM, Christopher Bongaarts <cab at umn.edu> wrote:
>
> We're using a custom URI for our current (token-based) two-factor, and
> plan to use another one for our replacement (unless someone else has an
> opinion on an existing one that matches up well with Duo...)

I'll offer my two cents re Duo :-)  First, the Duo solution depends on
an existing password, so the semantic you attach to the AuthnContext
URI depends on that password of course. Second, the term "Duo
solution" is too broad since there are many ways to achieve 2FA with
Duo. I draw the line between telephony and non-telephony based
solutions (which is where Duo itself draws the line). The Duo Mobile
app can be installed on *any* iOS platform (including iPad and iPod
Touch), *any* Android platform (including tablets) etc. Thus the Duo
Mobile app is where I draw the line. It provides more security (and
ironically, more usability) than methods based on telephony.

Tom


More information about the users mailing list