authn/Duo flow failure

Rory Larson rlarson1 at unl.edu
Tue Apr 4 10:19:55 EDT 2017


>> Trying to upgrade to 3.3.1, with a prior Duo installation

> [...] Or you can convert to the one provided by the project and remove the third party one.

Thanks.  Converting to the one provided by the project is exactly what I want to do, but I'm not sure how to do it.  The conf/authn/duo.properties file that comes with 3.3.1 seems to be a stub:

	# Duo integration settings

	# Note: If upgrading from pre-3.3 IdP versions, you will need to manually add a pointer
	# to this property file to idp.properties.

	idp.duo.apiHost = hostname
	idp.duo.applicationKey = key
	idp.duo.integrationKey = key
	idp.duo.secretKey = key

In the original installation, duo.properties was directly under conf.  For the upgrade, I copied the original values for these properties to duo.properties under conf/authn, added the optional "duo.failmode = safe", and changed the pointer to it in conf/idp.properties (idp.additionalProperties) to /conf/authn/duo.properties.  The old installation did not have the idp. prefixed to these property names, and the upgrade gives me errors when it does not have the plain unprefixed form.  If I do give it the plain duo.- form, it gives the error on loading the authn/Duo flow.

Thanks for the advice on Thursday, by the way.  I've reverted to the upgrade approach as recommended.

Rory


-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Monday, April 3, 2017 6:31 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: authn/Duo flow failure

On 4/3/17, 5:44 PM, "users on behalf of Rory Larson" <users-bounces at shibboleth.net on behalf of rlarson1 at unl.edu> wrote:

> Trying to upgrade to 3.3.1, with a prior Duo installation

If you're using somebody else's Duo implementation, which I would imagine you must be, then a) that's not supported by me and b) there are none that work reliably on 3.3 without work. You can find threads in the archive on the workarounds required, Chris Bongaarts posted some of that. Or you can convert to the one provided by the project and remove the third party one.

-- Scott


-- 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list