MCB SSO not requiring greater authentication methods

Ho, PeiQuan PeiQuan.Ho at tufts.edu
Wed Apr 8 16:11:38 EDT 2015


Hi,

                We're working on getting Shibboleth to work with the MCB here at Tufts.  Recently we noticed an issue where if a user has logged into an SP where the attributeResolverID for the MCB returns username/password, the user logs in fine.  But then if the same user logs into an SP where the attributeResolverID for the MCB returns DUO 2-factor authentication, the IDP does not go forward and require the two-factor and just lets the user into the SP.  Can you please provide some guidance as to why the MCB is failing to re-authenticate at the higher method?

Thanks,
-PQ

PeiQuan Ho
Tufts Technology Services (TTS)
169 Holland Street
Somerville, MA 02144
(617) 627-5147 (Work)

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150408/ab99595f/attachment.html 


More information about the users mailing list