Using Duo for per-SP-opt-in

Cantor, Scott cantor.2 at osu.edu
Wed Jan 27 10:19:54 EST 2016


On 1/27/16, 10:10 AM, "users on behalf of Jorj Bauer" <users-bounces at shibboleth.net on behalf of jorj at temple.edu> wrote:


>
>I did notice some other ... AuthnContextClass identifiers? ... that make 
>me wonder what the use cases were for these and how poorly they line up. 
>I need to go read more on the subject.
>
>   urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorUnregistered
>   urn:oasis:names:tc:SAML:2.0:ac:classes:MobileTwoFactorContract

Fair point, and to be honest I don't know how they line up with something like Duo. The context classes in SAML are from the Liberty Alliance and are often historical curiosities, especially stuff related to mobile.

Mobile there mostly refers to using mobile devices directly as authenticators, but eh, who knows. Might be close enough.

The main issue is that it locks everybody to talking about a specific technical method rather than a category of methods suitable for something so that systems can evolve, but you get that.

-- Scott



More information about the users mailing list