risk based authentication

Etan Weintraub eweintra at jhmi.edu
Thu Feb 18 14:38:49 EST 2016


At Hopkins, I wrote a custom system to plugin in to our WebSSO system that we use in front of Shibboleth (CA’s SiteMinder), and then leveraged different Auth Handlers/Methods to require different levels for sites, depending on what we were looking to use.

 

I’d be happy to talk with you about what we did.

 

-Etan E. Weintraub

Information Security Architect

IT at Johns Hopkins

Johns Hopkins at Mt. Washington

 <x-apple-data-detectors://4/> 5801 Smith Ave.

Davis Building  <x-apple-data-detectors://4/> Suite 3110B

 <x-apple-data-detectors://5/0> Baltimore, MD 21209

Phone:  <tel:667-208-6309> 667-208-6309

E-mail:  <mailto:eweintra at jhmi.edu> eweintra at jhmi.edu

 

From: users [mailto:users-bounces at shibboleth.net] On Behalf Of cneberg
Sent: Thursday, February 18, 2016 2:13 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: risk based authentication

 

What attributes of authentication and the user did you have mind for the decision?

Thanks,

Christopher

 

On Thu, Feb 18, 2016 at 10:25 AM, Liam Hoekenga <liamr at umich.edu <mailto:liamr at umich.edu> > wrote:

Is anyone doing risk based authentication with the IdP?  If so, how have you implemented it?

 

Liam


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net <mailto:users-unsubscribe at shibboleth.net> 

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160218/11664de5/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4825 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20160218/11664de5/attachment-0001.p7s>


More information about the users mailing list