Error in MFA with disallowed AUTHNCONTEXT + requested PasswordProtectedTransport
Leite, Zailo S.
zleite at caltech.edu
Mon Jul 10 13:17:22 EDT 2017
On Sun, 2017-07-02 at 14:51 +0000, Cantor, Scott wrote:
> >> I have a SP that requires PasswordProtectedTransport. If we set
> >> disallowedFeatures-ref="SAML2.SSO.FEATURE_AUTHNCONTEXT" in
> >> relying-party.xml, per the wiki, we get an error:
> >
> > That's the purpose of the feature, that's what it does.
>
> (By which I'm saying, its purpose is to prevent an SP from requesting something because you've chosen to define what it should get in your IdP configuration. The other option is to require signed requests so that only the SP itself can override the rule, which presumably it can't do since if it could request anything specific you wouldn't have configured this on the IdP side to begin with.)
>
> -- Scott
OK, thanks for the clarification, but what's the solution then? If I
don't use disallowedFeatures, the ordered list of principals won't be
enforced.
Z
More information about the users
mailing list