MFA attribute for CAS serviceValidate

John C. Pfeifer pfeifer at umd.edu
Wed Apr 12 13:34:03 EDT 2017


I am converting our IdP v3.3, which currently uses an external CAS server for authentication (and is also our Duo integration point), to use the built in login/mfa/duo flows and enable the CAS protocol bits. Everything is working just fine except…

In my current CAS server, I release an attribute value in the serviceValidate response which indicates if the user had done Duo at some point in the current SSO session.  I figure that I will need to script something in either the attribute resolver or filter but am unclear on how to detect if MFA had happened.

Much thanks for any guidance...

//
John Pfeifer
Division of Information Technology
University of Maryland, College Park



More information about the users mailing list