Duo login for shibboleth

Curry, Warren whcurry at ufl.edu
Thu Mar 24 14:59:27 EDT 2016


We at UF have multiple DUO setup in the 3.21 install.  

We need one for FISMA moderate users.   We need a second for a regular MFA user.  

Two distinct setups with the DUO vendor.      Just to add to use cases.   One set of DUO architecture runs on a fed certified RAMP.  

The other is there standard site license offering.   

These are two integrations.. 

whc

-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Thursday, March 24, 2016 12:08 PM
To: David Langenberg <davel at uchicago.edu>; Shib Users <users at shibboleth.net>
Subject: RE: Duo login for shibboleth

> You could, however, flip
> this request around and setup multiple Duo webSDK integrations with 
> your IdP.  That way you could have a context for "anything duo 
> supports" vs one for "anything except phone, trusted devices, and 
> trusted networks".  You'd then have the information you needed about 
> what the user did (or didn't do) when they performed the additional factor.

That's a bit of the long way around, but I guess so, yes. I'm working on what will eventually be the canonical way of integrating this into 3.3 and the code I started with had support for multiple Duo configs, probably that needs to be folded back in and I need to think about applying the tricks I used with JAAS. The JAAS validators can be told to map specific JAAS configs to specific Principal collections, this is basically the same idea. Thx for the suggestion.

-- Scott

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list