MFA result reuse with Duo.

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Wed Jan 18 14:11:50 EST 2017


This may have already been discussed.  If so I apologize for the repetition.

We are running all authn through MFA where authn/Password is the initial flow.  We then have transition scripting to determine if the relying party activates a Duo requirement.  In the scenario where there is a prior session where the Duo factor was NOT activated, and the user is now trying to access a service that should activate the Duo factor, the MFA reuse result is allowing that requirement to be ignored.

Is there a recommended method for this kind of MFA where Duo is IdP-initiated according to rules?

Thanks.

Josh O'Dowd
Software Systems Engineer / Identity Access Management
Central IT, University of Montana
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170118/6452b8a3/attachment.html>


More information about the users mailing list