ADFSv3 IdP3.3 differences from v2

Cantor, Scott cantor.2 at osu.edu
Fri Mar 24 18:13:25 EDT 2017


On 3/24/17, 5:50 PM, "users on behalf of O'Dowd, Josh" <users-bounces at shibboleth.net on behalf of Josh.O'Dowd at mso.umt.edu> wrote:

>  It suggests that for ADFS v2 and v3, that a duplicate authn/Password flow needs to be created, and wired for that MS
> Authentication Method.

We have ADFS SPs at OSU, and I haven't been required to support any new context class. If I did have to do so, then it would not be a big deal in the abstract, and it does not involve duplicating anything. The V2 authentication documentation has no relevance whatsoever to the V3 IdP.

But in this specific example, I would never allow an SP to request use of "password". With our Duo rollout, that would be flagged as a "what are you doing" issue and security here would take care of it.

> The doc indicates a need to address that issue again if using ADFSv3.

I haven't done that, and I haven't supported any of their made up attributes. It's been pretty much vanilla integrations for me on campus. I also have a variety of vendors using ADFS and none of them have ever issued requests with a non-standard context class.

Basically, you can treat ADFS like any other SP for the most part.
 
-- Scott




More information about the users mailing list