MCB with Duo and password as fallback

Cantor, Scott cantor.2 at osu.edu
Wed Aug 20 20:28:50 EDT 2014


On 8/20/14, 8:16 PM, "Paul Hethmon" <paul.hethmon at clareitysecurity.com>
wrote:
>
>So Duo is allowed to be used for password, but password is not allowed
>for Duo. Then, if you are wanting to force Duo, have the SP send only
>Duo. If the SP sends both password and Duo, then while one may be
>preferred by the order given, it still means both are acceptable.

Right, but the IdP today doesn't prefer the first one that can be tried,
but the first one that's already active. If the MCB does that too, it
shares that quirk. Whether you want to consider that a bug or not is up to
you, but I did/do consider it a bug in the IdP.

In V3, it's controlled with the idp.authn.favorSSO property, which
defaults true at the moment, but I'm still debating that. While it's
compatible that way, it's not really correct, and changing that behavior
doesn't really break anything.

-- Scott



More information about the users mailing list