IdP3 Force Authentication Context for select CAS services

Marvin Addison marvin.addison at gmail.com
Tue Aug 2 08:25:57 EDT 2016


On Mon, Aug 1, 2016 at 4:53 PM Cantor, Scott <cantor.2 at osu.edu> wrote:

> The IdP can default in the form of authentication to use based on a
> RelyingParty override, see the defaultAuthenticationMethods property on any
> of the SSO profile configurations. The CAS login config should have that
> property.
>

It does and that's the method that we use to selectively enable/disable 2FA
for select services. I would recommend defining a "2fa" group and tag those
services in your ServiceRegistry bean, then you can use a
RelyingPartyByGroup strategy to enable it for a number of services.

M <users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160802/033aa0d9/attachment.html>


More information about the users mailing list