IdP3 Force Authentication Context for select CAS services

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Mon Aug 1 16:47:35 EDT 2016


We are attempting to force 2FA for select SAML2 entities, and CAS services, using Duo.

I have had success on the SAML front, by following the implementation described in the IdP3 Wiki[1].  In that format, I am having success by adding, forceAuthn="true" authnContextClassRef="http://www.duosecurity.com/" to the SSO block in my SPs shibboleth2.xml config file.

The challenge now is to achieve the same for select CAS services.  I am not quite sure how to attack this.  Since I don't see a way to have a CAS client request forceAuthn for an authnContextClassRef, I am assuming I would need to somehow get the IdP to force the second factor context under a conditional trigger maybe?

Any thoughts by you smart folks is highly welcome.

Thanks.

Josh O'Dowd
Software Systems Engineer / Identity Access Management
Central IT, University of Montana

[1] https://wiki.shibboleth.net/confluence/display/IDP30/SP-driven+Duo+opt-in

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160801/53a9d2bc/attachment.html>


More information about the users mailing list