requiring 2FA for an SP
Michael A Grady
mgrady at unicon.net
Tue Oct 4 15:59:39 EDT 2016
> On Oct 4, 2016, at 2:51 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
>> I think this will be fairly trivial to do in 3.3 with the new MFA implementation.
>
> Nothing to do with 3.3 or that implementation.
>
>> In 3.2, you have a variety of unpalatable options unless you can, as Peter
>> mentioned, modify the metadata or AuthnRequests to do signaling by
>> AuthnContext.
>
> There is no signaling in metadata for this, never has been. The option is the same as always, modify defaultAuthenticationMethods for the relying party and require signed requests. I agreed to look at adding an option in 3.3 to block requesting AuthnContexts to avoid the signed requirement but the core mechanism is defaultAuthenticationMethods.
>
> -- Scott
See:
https://wiki.shibboleth.net/confluence/display/IDP30/Configuring+the+IdP+for+the+Multi-Context+Broker+Model#ConfiguringtheIdPfortheMulti-ContextBrokerModel-DefaultAuthenticationContext(method)foranSP
Expand the example to see configuration.
--
Michael A. Grady
IAM Architect, Unicon, Inc.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 842 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <http://shibboleth.net/pipermail/users/attachments/20161004/8af02121/attachment.sig>
More information about the users
mailing list