IdP3 Force Authentication Context for select CAS services
O'Dowd, Josh
Josh.O'Dowd at mso.umt.edu
Mon Aug 1 16:47:35 EDT 2016
We are attempting to force 2FA for select SAML2 entities, and CAS services, using Duo.
I have had success on the SAML front, by following the implementation described in the IdP3 Wiki[1]. In that format, I am having success by adding, forceAuthn="true" authnContextClassRef="http://www.duosecurity.com/" to the SSO block in my SPs shibboleth2.xml config file.
The challenge now is to achieve the same for select CAS services. I am not quite sure how to attack this. Since I don't see a way to have a CAS client request forceAuthn for an authnContextClassRef, I am assuming I would need to somehow get the IdP to force the second factor context under a conditional trigger maybe?
Any thoughts by you smart folks is highly welcome.
Thanks.
Josh O'Dowd
Software Systems Engineer / Identity Access Management
Central IT, University of Montana
[1] https://wiki.shibboleth.net/confluence/display/IDP30/SP-driven+Duo+opt-in
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160801/53a9d2bc/attachment.html>
More information about the users
mailing list