issue with research.gov ?

Cantor, Scott cantor.2 at osu.edu
Tue Aug 18 20:05:23 EDT 2015


On 8/18/15, 8:01 PM, "users on behalf of David Langenberg" <users-bounces at shibboleth.net on behalf of davel at uchicago.edu> wrote:



>I wish I could show you something cool & clever.  Unfortunately, I had to in the end eliminate Password from anywhere in my configs (only using PPT) and then gave my users a choice.  The distasteful choice was could use research.gov <http://research.gov> or they could be defaulted to 2FA.  Those who were negatively affected chose to opt-out of electing to force Duo.  Now, that said, things seem to work properly under IdPv3 (research.gov <http://research.gov>
> seems to at least see me).  I'll see if I can track down somebody who uses the site & get them to try Duo.

IIRC, when you were working through issues earlier, you said that you had associated Duo with the PPT context in the config.

Also, in general, the only hard constraint is at the end. Whatever the various flows are configured to handle, it's only the result at the end that's cross-checked (but unlike V2, that check is basically impossibly to circumvent, it won't respond with a context that doesn't match the request, to prevent a spec violation.

-- Scott



More information about the users mailing list