requiring 2FA for a service (Shibboleth 2 & MCB)

David Walker dwalker at internet2.edu
Thu Oct 15 19:49:55 EDT 2015


The current version of the MCB (for Shib 2) should be treating the
defaultAuthenticationMethod in relying-party.xml as if it were a context
requested by the SP, so if you set that to a context requiring MFA, it
should do what you want.  What I don't remember (and the GitHub issue
below doesn't illuminate) is whether it will override an explicit
request from the SP or if it's merely a default when the SP requests no
context.  Paul, if you're watching, do you remember?

By the way, this functionality was not in the initial release; see
https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues/11
for details. 

David


On 10/14/2015 07:02 PM, Cantor, Scott wrote:
> On 10/14/15, 9:51 PM, "users on behalf of IAM David Bantz" <users-bounces at shibboleth.net on behalf of dabantz at alaska.edu> wrote:
>
>
>
>> Seems it should be possible, setting the defaultAuthenticationMethod for this service in relying-party.xml
> That's nominally correct, but in V2 that isn't really quite saying that it requires that method. That tells it what to do in the absence of any other decision, but it has no way of enforcing what happened before it finishes up. I don't know if the MCB changes that, I guess it probably does.
>
> -- Scott
>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151015/bf0cd06f/attachment-0001.html>


More information about the users mailing list