MFA flow active result reuse--multiple Duo integrations or multiple Duo flows
Cantor, Scott
cantor.2 at osu.edu
Mon Jan 9 19:23:49 EST 2017
On 1/9/17, 6:44 PM, "users on behalf of Scott Koranda" <users-bounces at shibboleth.net on behalf of skoranda at gmail.com> wrote:
> It appears that the MFA flow determines reuse of an active
> result only by the name or flowId of the flow and does not
> consider the principal that was attached to that active result.
It definitely checks at the end step, and I'm fairly certain it should check before and given result reuse. It does, however, only *save* results based on the last result with a given ID, and will overwrite earlier ones.
> Is that correct?
I don't believe so.
> If so, then if I want two distinct Duo integrations to really
> be completely distinct (as if one were Duo and one were some
> other method like X.509 certificate) I need to define two
> distinct flows, say authn/Duo and authn/DuoOther, and manage
> them in the MFA transition strategy.
If you need the results to be active simultaneously, yes.
-- Scott
More information about the users
mailing list