Error in MFA with disallowed AUTHNCONTEXT + requested PasswordProtectedTransport
Leite, Zailo S.
zleite at caltech.edu
Mon Jul 10 14:22:43 EDT 2017
On Mon, 2017-07-10 at 17:24 +0000, Cantor, Scott wrote:
> > OK, thanks for the clarification, but what's the solution then?
>
> If an SP asks for something specific, you either let it (and give it what it asks for) or you stop it from asking or you accept that it will fail if it does. The only allowable outcomes to a request like this is "satisfy it or return an error". The blocking feature is just a way to force the second outcome rather than end up doing something you don't want done.
>
> An SP asking for "password" is probably broken because outside of some very unusual cases, that doesn't make any real sense. So it probably needs to be be fixed.
>
> > If I don't use disallowedFeatures, the ordered list of principals won't be
> > enforced.
>
> SAML requires that an SP asking for something get what it asks for. That's not something the IdP can ignore. We don't offer a "not compliant" mode.
>
> -- Scott
>
Sorry, I wasn't clear. What I mean is that if the solution proposed in
the wiki (use of an ordered list of principals) is not applicable if the
SP requests an AuthenticationMethod (and I have two so far, Code42 and
Slack, Password and PPT respectively), how do I force the MFA flow to
run?
Z
More information about the users
mailing list