Google 2sv instead of Duo for MFA in Shibboleth IdP?
Cantor, Scott
cantor.2 at osu.edu
Thu Oct 20 20:20:59 EDT 2016
> I'm suppressing commentary, just posting the question: has anyone
> compared, evaluated or deployed Google authenticator 2sv and in their IdP
> or know to what extent it would be possible?
AFAIK, that's just OATH, and we're planning to eventually implement it, it just didn't make 3.3, Duo was the higher priority both for my campus and the community in general. Given a token store / API, the actual flow to implement the login should be very simple in 3.3, but per the FIDO conversation I just had with a couple of people on the list, there's the question of how the token management/enrollment is done and by whom.
I would ask Rich what he meant by "your users will hate you". Is that a reference to the point that using the OATH apps like this implies separate registration of the authenticator app with each OATH service?
Using Google *authentication* with the IdP is really a different thing entirely. I would think that takes some more thought around policy and such since that implies using Google accounts directly in place of your own.
-- Scott
More information about the users
mailing list