MFA result reuse with Duo.
O'Dowd, Josh
Josh.O'Dowd at mso.umt.edu
Wed Jan 18 14:11:50 EST 2017
This may have already been discussed. If so I apologize for the repetition.
We are running all authn through MFA where authn/Password is the initial flow. We then have transition scripting to determine if the relying party activates a Duo requirement. In the scenario where there is a prior session where the Duo factor was NOT activated, and the user is now trying to access a service that should activate the Duo factor, the MFA reuse result is allowing that requirement to be ignored.
Is there a recommended method for this kind of MFA where Duo is IdP-initiated according to rules?
Thanks.
Josh O'Dowd
Software Systems Engineer / Identity Access Management
Central IT, University of Montana
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170118/6452b8a3/attachment.html>
More information about the users
mailing list