IdP3 Force Authentication Context for select CAS services
O'Dowd, Josh
Josh.O'Dowd at mso.umt.edu
Tue Aug 2 09:41:46 EDT 2016
Thanks guys,
That is what I was looking for.
Josh O’Dowd
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Marvin Addison
Sent: Tuesday, August 2, 2016 6:26 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: IdP3 Force Authentication Context for select CAS services
On Mon, Aug 1, 2016 at 4:53 PM Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
The IdP can default in the form of authentication to use based on a RelyingParty override, see the defaultAuthenticationMethods property on any of the SSO profile configurations. The CAS login config should have that property.
It does and that's the method that we use to selectively enable/disable 2FA for select services. I would recommend defining a "2fa" group and tag those services in your ServiceRegistry bean, then you can use a RelyingPartyByGroup strategy to enable it for a number of services.
M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160802/4b2f735f/attachment.html>
More information about the users
mailing list