MFA and attribute return

Greg Haverkamp gahaverkamp at lbl.gov
Fri Aug 25 17:04:26 EDT 2017


On Fri, Aug 25, 2017 at 12:39 PM, Richard Frovarp <richard.frovarp at ndsu.edu>
 wrote:
>
>  The problem is if idp.authn.flows is set to MFA, it isn't releasing any
> attributes, despite the fact that it is configured to release attributes.
> If I change that from MFA to Password, it obviously doesn't do the MFA
> check, but it also releases the attributes. No matter what that value is,
> testing via aacli.sh gives back the proper list of attributes.


To quote Scott from the linked thread: "Are you clearing the
AttributeResolutionContext like the example does, or not?"

http://shibboleth.1660669.n2.nabble.com/My-MFA-script-is-clearing-the-list-of-requested-attributes-tp7633443p7633460.html

Greg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170825/a7d207c5/attachment.html>


More information about the users mailing list