risk based authentication
Etan Weintraub
eweintra at jhmi.edu
Thu Feb 18 14:38:49 EST 2016
At Hopkins, I wrote a custom system to plugin in to our WebSSO system that we use in front of Shibboleth (CA’s SiteMinder), and then leveraged different Auth Handlers/Methods to require different levels for sites, depending on what we were looking to use.
I’d be happy to talk with you about what we did.
-Etan E. Weintraub
Information Security Architect
IT at Johns Hopkins
Johns Hopkins at Mt. Washington
<x-apple-data-detectors://4/> 5801 Smith Ave.
Davis Building <x-apple-data-detectors://4/> Suite 3110B
<x-apple-data-detectors://5/0> Baltimore, MD 21209
Phone: <tel:667-208-6309> 667-208-6309
E-mail: <mailto:eweintra at jhmi.edu> eweintra at jhmi.edu
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of cneberg
Sent: Thursday, February 18, 2016 2:13 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: risk based authentication
What attributes of authentication and the user did you have mind for the decision?
Thanks,
Christopher
On Thu, Feb 18, 2016 at 10:25 AM, Liam Hoekenga <liamr at umich.edu <mailto:liamr at umich.edu> > wrote:
Is anyone doing risk based authentication with the IdP? If so, how have you implemented it?
Liam
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net <mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160218/11664de5/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4825 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20160218/11664de5/attachment-0001.p7s>
More information about the users
mailing list