Duo IdPv3.3 c14n null principal.

Cantor, Scott cantor.2 at osu.edu
Thu Dec 29 12:45:27 EST 2016


> We don't allow the redirect to the service until the new password change
> form is completed; presented, validated, and processed via the
> authn/condition/expired-password sub-flow.  They're stuck until they
> comply.  Once they comply, we do not require them to re-authenticate.  That
> is when we do the manual c14n and fire a 'proceed' back to MFA, completing
> the authn/Password factor.

Hmm. Do you have the new password at that point? You could maybe tweak things a bit by essentially preparing the UsernamePasswordContext and then routing back to the Validate step. That's more along the lines of a supported piece of internal state.

-- Scott



More information about the users mailing list