2nd factor IdP AuthN conditional on user attribute

Keith Hazelton keith.hazelton at wisc.edu
Thu Feb 9 15:40:24 EST 2017


Thanks, all. We’re going to get with the program and upgrade to Shib IdP 3.3    --keith
___________________
On 2017-02-09, 14:35, "users on behalf of Rich Graves" <users-bounces at shibboleth.net on behalf of rgraves at carleton.edu> wrote:

    shibboleth-mfa-u2f-auth appears to hook similar to Unicon's Duo
    plugin, rather than Duo's own competing plugin. So it might work as is
    with 3.3, but it's more at risk. (Duo's strategy was to sneakily
    intercept Password without actually adding to idp.authn.flows, so
    theirs works in 3.3.)
    
    If you already have shibboleth-mfa-u2f-auth working with 3.2.1 then it
    shouldn't be too hard to figure out how to switch the flow on or off
    based on what UChicago and others did with shib-mfa-duo-auth. But as
    Scott said that's a dead end. Forward-looking options include:
    
    - Add the Duo layer, which is well supported with Shibb and Yubikey.
    How many users are you talking about? The first 10 are free.
    - Make the existing shibboleth-mfa-u2f-auth work in 3.3.
    - Sponsor the possibly substantial work for the next version of
    shibboleth-mfa-u2f-auth, or a forked or from-scratch reimplementation
    by someone else, designed to work with the completely new MFA
    framework in 3.3. Unless you can switch to Duo this is the only viable
    long-term option, but the timing sucks.
    -- 
    To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
    



More information about the users mailing list