IdP 3.2 and multiple Duo Applications

Cantor, Scott cantor.2 at osu.edu
Tue Dec 15 21:35:26 EST 2015


On 12/15/15, 9:32 PM, "users on behalf of Cantor, Scott" <users-bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:



>On 12/15/15, 9:20 PM, "Yavor Yanakiev" <yavor at nyu.edu> wrote:
>
>>The idea is to have just few, 3 or 4 Duo flows, which will be used by all SPs that fit in particular category. For example, some SPs will not use "Trusted Devices" setting in their flow.
>
>So tailoring the options, as opposed to identifying the application differently to Duo? That's different than what I was thinking.

Just a suggestion...

A login flow that had to support various options could be extended to derive options from applying a Predicate<ProfileRequestContext> at runtime.

Then you could pretty easily plug in just about any criteria you wanted to derive the options, reusing in many cases the condition beans that are already available.

-- Scott



More information about the users mailing list