2nd factor IdP AuthN conditional on user attribute
Keith Hazelton
keith.hazelton at wisc.edu
Thu Feb 9 15:40:24 EST 2017
Thanks, all. We’re going to get with the program and upgrade to Shib IdP 3.3 --keith
___________________
On 2017-02-09, 14:35, "users on behalf of Rich Graves" <users-bounces at shibboleth.net on behalf of rgraves at carleton.edu> wrote:
shibboleth-mfa-u2f-auth appears to hook similar to Unicon's Duo
plugin, rather than Duo's own competing plugin. So it might work as is
with 3.3, but it's more at risk. (Duo's strategy was to sneakily
intercept Password without actually adding to idp.authn.flows, so
theirs works in 3.3.)
If you already have shibboleth-mfa-u2f-auth working with 3.2.1 then it
shouldn't be too hard to figure out how to switch the flow on or off
based on what UChicago and others did with shib-mfa-duo-auth. But as
Scott said that's a dead end. Forward-looking options include:
- Add the Duo layer, which is well supported with Shibb and Yubikey.
How many users are you talking about? The first 10 are free.
- Make the existing shibboleth-mfa-u2f-auth work in 3.3.
- Sponsor the possibly substantial work for the next version of
shibboleth-mfa-u2f-auth, or a forked or from-scratch reimplementation
by someone else, designed to work with the completely new MFA
framework in 3.3. Unless you can switch to Duo this is the only viable
long-term option, but the timing sucks.
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list