requiring 2FA for a service (Shibboleth 2 & MCB)

IAM David Bantz dabantz at alaska.edu
Wed Oct 14 21:51:26 EDT 2015


Our IdP is configured now to require 2FA for those with a specific value of
an "assurance" attribute (based on group membership in the enterprise LDAP
directory).

Now I've been asked to require 2FA for anyone using a particular service
relying on this IdP (it's AWS if that makes any difference). That is,
whether or not they would be required to use 2FA based on the assurance
attribute, they do need 2FA to get authN asserted to AWS. Is that feasible?

Seems it should be possible, setting the defaultAuthenticationMethod for
this service in relying-party.xml, and the right configuration in
multi-context-broker.xml.  For the life of me though I can't keep context
and method straight, as the authN "methods" in relying-party.xml look like
the "context" names in multi-context-broker.xml.

If you've set up something parallel, or have a good idea of how I configure
for this result, please enlighten me.

Thank you,

David Bantz
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151014/1129523b/attachment.html>


More information about the users mailing list