IdP v2 to v3 migration success story

Michael A Grady mgrady at unicon.net
Mon Jul 20 10:50:58 EDT 2015


> On Jul 20, 2015, at 8:53 AM, Cantor, Scott <cantor.2 at OSU.EDU> wrote:
> 
> On 7/18/15, 10:16 PM, "users on behalf of Paul B. Henson" <users-bounces at shibboleth.net on behalf of henson at cpp.edu> wrote:
>> 
>> I apologize that I'm not familiar in detail with MFA in either a CAS or
>> idp context at this point, but I'd be curious which of those options
>> would likely lead to the best support? Will the idp MFA mechanisms work
>> for the CAS protocol? If idp authentication is delegated to a CAS
>> server, would the CAS MFA mechanisms be available to the idp for SAML
>> clients?
> 
> Authentication in either case is totally outside the scope of the rest of the interactions whether it's MFA or something else. The exception is ECP, which cannot in general accomodate a browser-based login.

If you are deferring authentication to CAS, the "Shib to CAS" mechanisms still lack functionality in communicating the requested authentication context from the SP, and the actual authentication context that was satisfied on the CAS side. So you could run into problems when you have an SP actually requesting a specific form of authentication.

Now the identity of the SP is passed to CAS, so you can still drive 2Factor/MFA based on that, or the user, etc., but not the requested authn context back/forth.


--
Michael A. Grady
IAM Architect, Unicon, Inc.



More information about the users mailing list