MCB SSO not requiring greater authentication methods
Paul Hethmon
paul.hethmon at clareitysecurity.com
Fri Apr 10 11:55:40 EDT 2015
The correct (and easiest) way to do that is to have the SP request it. Either initially or it could send the user back to the IdP with the higher context value to “upgrade” their authentication.
The MCB does a lot, but it can’t mind read the SP.
> On Apr 10, 2015, at 11:47 AM, Ho, PeiQuan <PeiQuan.Ho at tufts.edu> wrote:
>
> The reason we are using a scripted attribute is because we want to give the SP the option of offering user opt-in two-factor. We maintain the user opt-in information in the backend and the IDP needs to determine the value for each SP and user before deciding which authentication method to present.
-----
Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com
More information about the users
mailing list