MCB SSO not requiring greater authentication methods
Cantor, Scott
cantor.2 at osu.edu
Thu Apr 9 12:15:44 EDT 2015
On 4/9/15, 11:27 AM, "Ho, PeiQuan" <PeiQuan.Ho at tufts.edu> wrote:
>But, what we're looking to do is have SPs point to an IDP and then the IDP will choose an authentication method to use for the SP based on a calculated value.
That's not the IdP's role, generally speaking. The SP, if it cares, asks for what it wants, and the IdP tries to satisfy it.
Absent the MCB, the IdP's RelyingParty settings can be used to set a default authentication method string to use for an SP, but the V2 IdP will always favor SSO and reuse an existing result if the SP doesn't specifically disallow it in its request.
V3 is very different in this area and has different features and more control over what the IdP will do, so it's more generally supportive of making the IdP decide these questions.
-- Scott
More information about the users
mailing list