IDPv3 and Unicon Duo Plugins and RemoteUser Flow and AWS
David Walker
dwalker at internet2.edu
Mon Oct 12 12:48:17 EDT 2015
You still need to have something in Shib, if you want to respond to
federated requests for MFA, to signal your SSO when it needs to do MFA.
David
On 10/12/2015 06:41 AM, David Langenberg wrote:
> I agree with Max, put Duo on your SSO system, if that's Cosign, then that's where Duo needs to be. Shib should be invisible to the user in these kinds of setups.
>
> Dave
>
>> On Oct 12, 2015, at 7:32 AM, Mark K. Miller <max at psu.edu> wrote:
>>
>>
>> Since the IdPs currently use Cosign for authentication, it would seem logical that the Duo integration would need to happen at the Cosign UI.
>>
>> Any other work integrating Duo with authentication pieces not being used by the IdP config would seem irrelevant.
>>
>> Hope that helps,
>>
>> Max
>>
>> On Sat, 10 Oct 2015, Christopher J. Hubing wrote:
>>
>>> After what I consider to be doing my due diligence in reading the docs, googling, and testing, I need some help.
>>>
>>> I can't seem to get either Duo plugin working with our config. Our IDPs do not do the AuthN, we use Cosign.
>>>
>>> I cranked up the logging to DEBUG and I don't see anything related to duo in the logs.
>>>
>>> ______________________________________________________________________
>>> Christopher J. Hubing Information Technology Services
>>> cjh at psu.edu Services and Solutions
>>> +1 814 865 8772 Pennsylvania State University
>>> http://www.personal.psu.edu/cjh
>>> --
>>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>>>
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
> --
> David Langenberg
> Identity & Access Management Architect
> The University of Chicago
>
More information about the users
mailing list