Shibboleth v3 + FIDO UAF

Cantor, Scott cantor.2 at osu.edu
Wed Oct 19 10:17:49 EDT 2016


> On 19/10/16 15:42, Cantor, Scott wrote:
> > https://github.com/Ratler/shibboleth-mfa-u2f-auth
> 
> I stumbled upon that one before, it's not from Yubico, but interesting
> nonetheless.

I thought he worked for them, my mistake if not.

> Lot of work indeed. Generally speaking, wouldn't it better to leave
> things like user+token management and OTP verification out of the IdP?

If we do that,weI would have to have an API to code to or design one. It also means people have to have those pieces in place to do anything with it.

Also, we're in competition, for better or worse, with products that don't leave this out of the IdP, or perhaps I should say have turned their offerings into IdPs.

> There are multiple vendors offering "authentication servers" which do
> just that and can typically be integrated via RADIUS. (incoming dev list
> post about RADIUS) That would avoid adding a bunch of complexity in the
> IdP.

You can't do U2F with RADIUS, and I don't think that having an additional web-based component you have to deploy is a good direction for us to support a feature. That's tantamount to going back to requiring a separate SSO service.

I haven't committed to doing anything at this point. If people weigh in and would rather we spend time on other things, that's ok, but historically "you can do this but it requires these extra things" has been more or less taken as "you don't support it". People want a turnkey solution or they just write it off.

-- Scott



More information about the users mailing list