MCB with Duo and password as fallback

Cantor, Scott cantor.2 at osu.edu
Wed Aug 20 22:51:29 EDT 2014


On 8/20/14, 10:46 PM, "Wessel, Keith" <kwessel at illinois.edu> wrote:

>Correct: strong auth doesn't work if you also allow weak. Our idea is to
>use the authncontext passed back into the application to see how the user
>authenticated and grant access accordingly.

Oh, I know. I'm just saying that allowing both at the app means the user
has every incentive to try and do as little as he/she can, and you have
the problem of the lack of privilege once they login and realize they
should have just taken their phone out.

I know that's what you're trying to fix by listing Duo first, and that's
why I fixed this in the IdP redesign.

-- Scott



More information about the users mailing list