MCB SSO not requiring greater authentication methods

Caskey, Paul pcaskey at utsystem.edu
Fri Apr 10 15:55:45 EDT 2015


Good news!  We are migrating an SP to require 2-factor and the SP can't specify a method until everyone has 2-factor capability.  In the meantime, if we can guarantee the SP that all logins to the SP are forcing 2-factor, they will re-enable certain functionality that had been turned off in the absence of 2-factor.

Thanks for everything!


> -----Original Message-----
> From: users-bounces at shibboleth.net [mailto:users-
> bounces at shibboleth.net] On Behalf Of Paul Hethmon
> Sent: Friday, April 10, 2015 2:51 PM
> To: Shibboleth Users
> Subject: Re: MCB SSO not requiring greater authentication methods
> 
> Paul,
> 
> This page on github shows you the issues list:
> 
> https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues
> 
> As for answers:
> 
> 1. I want to say 1.2.4 but there is one edge case not handled I need to fix.
> That’s issue #19. Actually, the issue may not have the detail as it was
> reported on the MCB mailing list.
> 2. It allows you to specify the method, but it only uses it if the SP does not
> send a method. So it is not an override, just a default if no other value was
> given.
> 
> cheers,
> 
> Paul
> 
> 
> > On Apr 10, 2015, at 3:42 PM, Caskey, Paul <pcaskey at utsystem.edu> wrote:
> >
> > Thanks, Paul.
> >
> > I'm not sure exactly what I'm referring to, I don't speak git unfortunately
> and don't see an obvious place on the github page to look at filed bugs.  I was
> going on things that informed people had told me in the not-too-distant
> past...
> >
> > So, let me just ask 2 questions:
> > 1. What version of the MCB is the best/recommended in terms of stability
> and functionality?
> > 2. Does that version allow me to specify 'defaultAuthenticationMethod' in
> the relying-party config and force the specified method for all logins to that
> SP?
> >
> >
> > Thanks again!
> >
> >
> >
> >> -----Original Message-----
> >> From: users-bounces at shibboleth.net [mailto:users-
> >> bounces at shibboleth.net] On Behalf Of Paul Hethmon
> >> Sent: Friday, April 10, 2015 2:31 PM
> >> To: Shibboleth Users
> >> Subject: Re: MCB SSO not requiring greater authentication methods
> >>
> >> Paul,
> >>
> >> Are you referring to Github issue #11? That one was fixed in version
> >> 1.2.1. I think the only open issue right now is #19. The others are
> >> not marked as fixed, but are fixed in the latest version on Github.
> >>
> >>> On Apr 10, 2015, at 11:39 AM, Caskey, Paul <pcaskey at utsystem.edu>
> >> wrote:
> >>>
> >>> So, do you think it will ever be possible to specify the authn
> >>> method in
> >> relying-party.xml (i.e. will that bug get fixed?)?
> >>>
> >>>
> >>
> >> Paul
> >>
> >> -----
> >> Paul Hethmon
> >> Chief Software Architect
> >> paul.hethmon at clareitysecurity.com
> >>
> >>
> >> --
> >> To unsubscribe from this list send an email to users-
> >> unsubscribe at shibboleth.net
> > --
> > To unsubscribe from this list send an email to
> > users-unsubscribe at shibboleth.net
> 
> -----
> Paul Hethmon
> Chief Software Architect
> paul.hethmon at clareitysecurity.com
> 
> 
> --
> To unsubscribe from this list send an email to users-
> unsubscribe at shibboleth.net


More information about the users mailing list