Duo login for shibboleth

Walter Forbes Hoehn (wassa) wassa at memphis.edu
Thu Mar 24 11:53:30 EDT 2016


Maybe not pertinent to this list, but yesterday before this came up here I posted a comment in the draft of the “InCommon Base Level MFA Profile” asking if it should be clarified whether the “http://id.incommon.org/assurance/mfa-base-level" authentication context could be asserted in this sort of scenario.

-WFH



On Mar 24, 2016, at 10:26 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
> 
>> Are we discussing "trusted networks" in the Enterprise Edition or the
>> advance geo-location features in the Platform Edition?
> 
> Trusted networks primarily, as well as time based bypass (the latter moreso really, but in the end it's all of a piece).
> 
>> Using trusted networks is a policy decision that states being on that network
>> satisfies MFA. Whether this is good or bad policy is up for debate.
> 
> I'm not asking people to agree it's bad policy, I'm asking for a third option that allows Duo to work any way it's told to but for the IdP to get enough information to accurately reflect the outcome if I don't happen to think that those are equivalent outcomes. I don't think everybody will agree. As far as I'm able to tell, the tenor of the InCommon discussion has been that it's not equivalent, but that remains to be seen I guess.
> 
> When you hand off with a frame like that, you are giving up a great deal of control and it's really important that you don't also give up visibility into the outcome.
> 
> -- Scott
> 
> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list