Shibboleth v3 + FIDO UAF

Etienne Dysli-Metref etienne.dysli-metref at switch.ch
Wed Oct 19 10:08:47 EDT 2016


On 19/10/16 15:42, Cantor, Scott wrote:
> https://github.com/Ratler/shibboleth-mfa-u2f-auth

I stumbled upon that one before, it's not from Yubico, but interesting
nonetheless.

> I just concluded that using their demo server wasn't really viable,
> and if we were going to do this for real, we need a real token
> registration UI along with it. I didn't have time to do that but I did
> have time to build out the layer we needed to start supporting flows
> that need users to authenticate themselves to the IdP. So we can give
> people the ability to login with a password to register a token and then
> require the token to get back in to manage their account, etc.

Lot of work indeed. Generally speaking, wouldn't it better to leave
things like user+token management and OTP verification out of the IdP?
There are multiple vendors offering "authentication servers" which do
just that and can typically be integrated via RADIUS. (incoming dev list
post about RADIUS) That would avoid adding a bunch of complexity in the IdP.

  Etienne


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20161019/5369b571/attachment.sig>


More information about the users mailing list