IdP 3.2 and DuoSecurity options

Curry, Warren whcurry at ufl.edu
Fri Jan 1 12:17:49 EST 2016


UF is also using a Unicon version.  That we upgraded a few days before Christmas.  Initial testing was successful.  We will be doing a full feature test next week.
We were having issues with forced auth in version 3.1..  Moved to 3.21 with a reasonable straight forward process. Unicon provided us some insight that saved time.

We are handling 2 distinct Duo contexts, Bronze, and password protected.  We were seeing some issues with the handling of unspecified.   This will be shaken out in the next set of testing.

Sent from my Verizon Wireless 4G LTE DROID
On Dec 31, 2015 1:21 PM, Rich Graves <rgraves at carleton.edu> wrote:
> As for 3.2. I've been testing the Unicon module with 3.2 on latest Jetty, and aside from a minor issue with Duo.vm not handling $requestContext properly, it seems to work just fine.

Hmm, maybe I'll try it again. The instructions didn't exactly apply, as some paths have changed.

I'm also giving the Duo package a try. It has some nice fail-safe behavior (shib-mfa-duo-auth issue #9). It doesn't do authentication contexts as "correctly" as Unicon's version, so I could not make specific SPs demand Duo (or Gold/Silver), but I don't currently need that feature. All I really want is to be able to toggle Duo on and off with a per-user LDAP attribute, which looks doable either at the Spring level or by injecting the LDAP call into their DuoShibboleth.java.
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160101/7405c894/attachment.html>


More information about the users mailing list