MCB SSO not requiring greater authentication methods
Cantor, Scott
cantor.2 at osu.edu
Thu Apr 9 12:40:18 EDT 2015
On 4/9/15, 12:33 PM, "Caskey, Paul" <pcaskey at utsystem.edu> wrote:
>Please correct if I'm wrong, but you could use a scripted attribute definition in the resolver for your MCB/assurance attribute and it would see the SP's ID and could just not issue 'password' as an acceptable method for that user in the case where you want to force 2-factor, correct?
It depends on whether/how the MCB populates the resolution context that ends up in the scripting layer with that information or not. It's not the IdP-proper running the resolver in this case, it's a sort of extra resolver invocation with a fair amount of mocked up context, at least if it's done how that sort of thing usually gets done with the old APIs.
-- Scott
More information about the users
mailing list