IDP 3.3 MFA flow -- working example
Cantor, Scott
cantor.2 at osu.edu
Wed Jan 18 14:37:50 EST 2017
On 1/18/17, 2:22 PM, "users on behalf of Sheldon, Nathan I" <users-bounces at shibboleth.net on behalf of Nathan.Sheldon at ucsf.edu> wrote:
> That fixed the issue. I’d like to suggest adding a note about the need to change the idp.authn.flows property to
> "idp.authn.flows = MFA” in the idp.properties file to the DuuoAuthnConfiguration wiki article, just to save others time on
> this. The “General Configuration” section of that article makes Duo setup seem more simplistic than it actually is.
Duo doesn't imply the MFA feature, they're not dependent. I'll double check what the MFA page says, but that's the relevant page and I thought it did say that.
> This forces Duo 2-factor auth on all login attempts (regardless of multi-factor authentication context).
That's acceptable assuming the MFA flow's set of supported Principals includes only values that would be consistent with use of Password + Duo. Meaning password contexts would be fine, but if something requested, say, Kerberos, it's important to make sure that's not going to run them. That should be generally true by default but for the archive it's important to note.
It's very easy to configure the IdP to lie, and you shouldn't do that.
-- Scott
More information about the users
mailing list