IDP 3.3 MFA flow -- checking to see if an authn context class ref was requested
Leite, Zailo S.
zleite at caltech.edu
Fri Dec 16 13:22:50 EST 2016
I'll try that, thanks. How do you import on the script? I'm getting
"AuthnContextClassRefPrincipal is not defined" error. I suppose I need
the package net.shibboleth.idp.saml.authn.principal?
Z
On Mon, 2016-12-05 at 10:19 -0800, Jim Fox wrote:
> >
> > First, I see I can use the isAcceptable method (as included in the distributed example) to see if a requested method has been satisfied. But I'm curious, in this case, about requested methods that haven't been satisfied - namely Duo. How can I get a list of requested authentication context classes? I've looked at the MFA context and authentication context in the JavaDocs, but I don't see anything to help me in those.
> >
> >
> I do something like this (to see if token was requested):
>
> authCtx = input.getSubcontext("net.shibboleth.idp.authn.context.AuthenticationContext");
> rpCtx = authCtx.getSubcontext("net.shibboleth.idp.authn.context.RequestedPrincipalContext");
> if (rpCtx != null) {
> rps = rpCtx.getRequestedPrincipals();
> tkp = new AuthnContextClassRefPrincipal("urn:oasis:names:tc:SAML:2.0:ac:classes:TimeSyncToken");
> if (rpCtx.getRequestedPrincipals().contains(tkp)) {
> logger.debug("RP requested token login");
> }
> }
>
>
> Jim
More information about the users
mailing list