IdP3 Force Authentication Context for select CAS services
Cantor, Scott
cantor.2 at osu.edu
Mon Aug 1 16:53:26 EDT 2016
> We are attempting to force 2FA for select SAML2 entities, and CAS services,
> using Duo.
The IdP can default in the form of authentication to use based on a RelyingParty override, see the defaultAuthenticationMethods property on any of the SSO profile configurations. The CAS login config should have that property.
In SAML, that's possibly to circumvent since the SP can request its own rules, but if that's not the case with CAS, it should work reliably.
ForceAuthn is a different issue from controlling the type of login. I don't know if CAS has the equivalent feature, but that's where it would really need to be.
-- Scott
More information about the users
mailing list