MCB with Duo and password as fallback
Paul Hethmon
paul.hethmon at clareitysecurity.com
Wed Aug 20 21:13:13 EDT 2014
On Aug 20, 2014, at 8:28 PM, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
So Duo is allowed to be used for password, but password is not allowed
for Duo. Then, if you are wanting to force Duo, have the SP send only
Duo. If the SP sends both password and Duo, then while one may be
preferred by the order given, it still means both are acceptable.
Right, but the IdP today doesn't prefer the first one that can be tried,
but the first one that's already active. If the MCB does that too, it
shares that quirk. Whether you want to consider that a bug or not is up to
you, but I did/do consider it a bug in the IdP.
MCB will satisfy the requested AuthnContext that meets the requirements between what the SP requested and what the user is allowed. It also allows the administrator to specify that one context can satisfy another context, yielding an ordered list. What complicates it more at this point, is that contexts are satisfied by methods. So, a method being the actual way a user authenticates. A given method can be specified to satisfy multiple context values which ends up rendering them the same in practice. That is because when a user authenticates successfully, they have completed a method. Then any context which uses that method can be satisfied.
So it ends up allowing the ordering of contexts and restricting which contexts a user is allowed.
Paul
Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com<mailto:paul.hethmon at clareitysecurity.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140821/f032495f/attachment.html
More information about the users
mailing list