AuthenticationContext with MFA

Eric Goodman Eric.Goodman at ucop.edu
Fri Aug 11 17:37:27 EDT 2017


>> I'm just curious if there are known bad SPs that are going to barf if 
>> they don't see a well-known AuthnContextClassRef, such as 
>> PasswordProtectedTransport, in the response.

>Some, I imagine. We have all employees using Duo with our HR system. 
>Random browsing of services would probably have broken something if 
>it were common, but that doesn't mean anyting in the aggregate.

I'd love to hear any statistics on this you come across. I'd like to recommend that we return the MFA context whenever it's used as long as it doesn't violate the request (i.e., if they ask for PPT return PPT, if the ask for MFA or unspecified return MFA), probably with some flag/mechanism to override for any (hopefully few) broken SPs. But I'd also like to know if that would end up being a recommendation for a DoA approach.

Thanks!

--- Eric 


More information about the users mailing list