Duo IdPv3.3 c14n null principal.
O'Dowd, Josh
Josh.O'Dowd at mso.umt.edu
Thu Dec 29 13:32:07 EST 2016
No, I like the idea. I'll give it a go and see if that works out. If I can get this going in a supported fashion, that is ideal.
Thanks again.
Cheers.
Josh
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Thursday, December 29, 2016 11:27 AM
To: Shib Users <users at shibboleth.net>
Subject: RE: Duo IdPv3.3 c14n null principal.
> So you are suggesting that if I also set that password in to the UPC
> and exit state back to ValidateUsernamePassword, that would
> effectually reauthenticate the user properly without sending them back
> to the login page, correct?
Yes. The Display/Validate steps are decoupled and don't have any interdependencies other than the context, which is under the AuthenticationContext, and there's no reason that would be changing.
The Display is an extraction step to populate the UPC. If something else does that, the Validate step won't know the difference.
Obviously it's less efficient to revalidate and there's the chance that something could fail for some other reason I suppose.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list