MCB SSO not requiring greater authentication methods
Cantor, Scott
cantor.2 at osu.edu
Wed Apr 8 16:31:47 EDT 2015
On 4/8/15, 8:11 PM, "Ho, PeiQuan" <PeiQuan.Ho at tufts.edu> wrote:
> We’re working on getting Shibboleth to work with the MCB
>here at Tufts. Recently we noticed an issue where if a user has logged
>into an SP where the attributeResolverID for the MCB returns
>username/password, the user logs in fine. But then if the same user logs
>into an SP where the attributeResolverID for the MCB returns DUO 2-factor
>authentication, the IDP does not go forward and require the two-factor
>and just lets the user into the SP.
I'm not going to speak for the MCB, but what you're describing in the
abstract is simply wrong. The attribute being resolved has nothing to do
with the SP, it's about the user's ability to use other methods in
general. If the SP doesn't request anything in particular, the existing
password authentication context is perfectly acceptable, and the MCB
*should* do exactly what you described.
-- Scott
More information about the users
mailing list