Error in MFA with disallowed AUTHNCONTEXT + requested PasswordProtectedTransport

Leite, Zailo S. zleite at caltech.edu
Mon Jul 10 13:17:22 EDT 2017


On Sun, 2017-07-02 at 14:51 +0000, Cantor, Scott wrote:
> >> I have a SP that requires PasswordProtectedTransport. If we set
> >> disallowedFeatures-ref="SAML2.SSO.FEATURE_AUTHNCONTEXT" in
> >> relying-party.xml, per the wiki, we get an error:
> >
> > That's the purpose of the feature, that's what it does.
> 
> (By which I'm saying, its purpose is to prevent an SP from requesting something because you've chosen to define what it should get in your IdP configuration. The other option is to require signed requests so that only the SP itself can override the rule, which presumably it can't do since if it could request anything specific you wouldn't have configured this on the IdP side to begin with.)
> 
> -- Scott

OK, thanks for the clarification, but what's the solution then? If I
don't use disallowedFeatures, the ordered list of principals won't be
enforced.

Z


More information about the users mailing list