IdP3 Force Authentication Context for select CAS services
Marvin Addison
marvin.addison at gmail.com
Tue Aug 2 08:25:57 EDT 2016
On Mon, Aug 1, 2016 at 4:53 PM Cantor, Scott <cantor.2 at osu.edu> wrote:
> The IdP can default in the form of authentication to use based on a
> RelyingParty override, see the defaultAuthenticationMethods property on any
> of the SSO profile configurations. The CAS login config should have that
> property.
>
It does and that's the method that we use to selectively enable/disable 2FA
for select services. I would recommend defining a "2fa" group and tag those
services in your ServiceRegistry bean, then you can use a
RelyingPartyByGroup strategy to enable it for a number of services.
M <users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160802/033aa0d9/attachment.html>
More information about the users
mailing list