Duo IdPv3.3 c14n null principal.
Cantor, Scott
cantor.2 at osu.edu
Thu Dec 29 12:45:27 EST 2016
> We don't allow the redirect to the service until the new password change
> form is completed; presented, validated, and processed via the
> authn/condition/expired-password sub-flow. They're stuck until they
> comply. Once they comply, we do not require them to re-authenticate. That
> is when we do the manual c14n and fire a 'proceed' back to MFA, completing
> the authn/Password factor.
Hmm. Do you have the new password at that point? You could maybe tweak things a bit by essentially preparing the UsernamePasswordContext and then routing back to the Validate step. That's more along the lines of a supported piece of internal state.
-- Scott
More information about the users
mailing list