Shibboleth v3 + FIDO UAF

Klingenstein, Nate nklingenstein at calstate.edu
Tue Oct 18 21:28:36 EDT 2016


Glaidson,

Your link appears to be to a Shibboleth 2.x page, so I wouldn't use it verbatim.  I know nothing in particular about FIDO UAF, so consider that in this answer.

it looks like FIDO UAF is its own protocol, and it's not a small one.

https://fidoalliance.org/specs/fido-uaf-v1.0-ps-20141208/fido-uaf-protocol-v1.0-ps-20141208.html

I would expect you need to write a modest custom integration into the Webflow of your login flow, hopefully based on an existing usable library if you can find a reasonable one.

https://fidoalliance.org/certification/fido-certified/

I can now explain how to do this with 3.2.1, which is why, if I were you, I'd develop against 3.3 and this:

https://wiki.shibboleth.net/confluence/display/IDP30/MultiFactorAuthnConfiguration

using the Duo, a competing vendor, flow as an example:

https://wiki.shibboleth.net/confluence/display/IDP30/DuoAuthnConfiguration

Hope this helps anyway,
Nate.

On Oct 18, 2016, at 5:54 PM, Glaidson Verzeletti <verzeletti at gmail.com<mailto:verzeletti at gmail.com>> wrote:

Hi,

I'm need to integrate shibboleht IdP v3 with FIDO UAF, as second authentication factor.

Until now I just found documentatin about multi factor login using the yubico (fido u2f) [1].

Does anyone have any idea of how to integrate these services?


I would appreciate your help.

Regards,
Glaidson.



[1] https://wiki.shibboleth.net/confluence/display/SHIB2/Multi+Factor+Login+Handler
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161019/c8904116/attachment.html>


More information about the users mailing list