IdP3 Force Authentication Context for select CAS services

Cantor, Scott cantor.2 at osu.edu
Mon Aug 1 16:53:26 EDT 2016


> We are attempting to force 2FA for select SAML2 entities, and CAS services,
> using Duo.

The IdP can default in the form of authentication to use based on a RelyingParty override, see the defaultAuthenticationMethods property on any of the SSO profile configurations. The CAS login config should have that property.

In SAML, that's possibly to circumvent since the SP can request its own rules, but if that's not the case with CAS, it should work reliably.

ForceAuthn is a different issue from controlling the type of login. I don't know if CAS has the equivalent feature, but that's where it would really need to be.

-- Scott



More information about the users mailing list