requiring 2FA for an SP

IAM David Bantz dabantz at alaska.edu
Tue Oct 4 15:43:26 EDT 2016


Because AFAIK the vended SP knows nothing about authN context - certainly
not our locally defined 2FA class.

David

On Tue, Oct 4, 2016 at 11:29 AM, Peter Schober <peter.schober at univie.ac.at>
wrote:

> * IAM David Bantz <dabantz at alaska.edu> [2016-10-04 21:18]:
> > I think it should be possible to configure a relying party to require a
> 2FA
> > authN context or method, presumably in relying-party.xml but perhaps in
> the
> > local copy of metadata for the SP, but I've been unable to locate correct
> > syntax.
>
> Is the SP requesting an authentication context class?
> If not, why not?
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161004/6732ee6a/attachment.html>


More information about the users mailing list