MFA and attribute return

Richard Frovarp richard.frovarp at ndsu.edu
Mon Aug 28 11:21:24 EDT 2017


On 08/25/2017 04:04 PM, Greg Haverkamp wrote:
> On Fri, Aug 25, 2017 at 12:39 PM, Richard Frovarp 
> <richard.frovarp at ndsu.edu <mailto:richard.frovarp at ndsu.edu>> wrote:
>
>     The problem is if idp.authn.flows is set to MFA, it isn't
>     releasing any attributes, despite the fact that it is configured
>     to release attributes. If I change that from MFA to Password, it
>     obviously doesn't do the MFA check, but it also releases the
>     attributes. No matter what that value is, testing via aacli.sh
>     gives back the proper list of attributes.
>
>
> To quote Scott from the linked thread: "Are you clearing the 
> AttributeResolutionContext like the example does, or not?"
>
> http://shibboleth.1660669.n2.nabble.com/My-MFA-script-is-clearing-the-list-of-requested-attributes-tp7633443p7633460.html
>
> Greg

Yeah, problem was not clearing the context. I don't know that I would 
have ever found that post. Thanks for the help.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170828/dec36f8b/attachment.html>


More information about the users mailing list