AuthenticationContext with MFA
Cantor, Scott
cantor.2 at osu.edu
Fri Aug 11 17:44:07 EDT 2017
On 8/11/17, 5:37 PM, "users on behalf of Eric Goodman" <users-bounces at shibboleth.net on behalf of Eric.Goodman at ucop.edu> wrote:
> I'd love to hear any statistics on this you come across. I'd like to recommend that we return the MFA context whenever it's used
> as long as it doesn't violate the request (i.e., if they ask for PPT return PPT, if the ask for MFA or unspecified return MFA),
> probably with some flag/mechanism to override for any (hopefully few) broken SPs. But I'd also like to know if that would end up
> being a recommendation for a DoA approach.
I certainly am returning the MFA value, and I've yet to run into anything that broke, so I definitely wouldn't call it a DOA approach. It's been over a year now.
I don't think there's any particularly easy way to override this in a fine grained way, what you'd pretty much have to do is forcibly set a defaultAuthenticationMethod for the broken SP(s) to get them to effectively request something else.
-- Scott
More information about the users
mailing list