MCB and defaultAuthenticationMethod

Paul Hethmon paul.hethmon at clareitysecurity.com
Tue Feb 4 19:37:04 EST 2014


No. It strictly looks at the MCB configuration. If the SP doesn't send an authentication context then the list as you configured will be used.

Paul


(Please enjoy the autocorrect features if this phone)

On Feb 4, 2014, at 5:38 PM, "Scott Koranda" <skoranda at gmail.com<mailto:skoranda at gmail.com>> wrote:

Hello,

My question concerns the Multi Context Broker (MCB) login handler detailed at

https://wiki.shibboleth.net/confluence/display/SHIB2/Multi-Context+Broker

I understand that the <initialAuthContext> configuration element controls "...a list of the authentication context values you as the administrator wish to present to the user" if the user has no existing session with the IdP.

In the event that the user does not have any existing session with the IdP and the SP has not requested any authentication context does the value for the defaultAuthenticationMethod attribute on the <RelyingParty> element corresponding to the SP factor at all into determining which choices are shown to the user? Is the defaultAuthenticationMethod used to filter the list of choices?

Thanks,

Scott K
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140205/2b33114a/attachment-0001.html 


More information about the users mailing list