Forcing Duo by Service Provider

Andrew Morgan morgan at orst.edu
Wed Mar 29 20:29:34 EDT 2017


On Wed, 29 Mar 2017, Cantor, Scott wrote:

> On 3/29/17, 11:56 AM, "users on behalf of Brandon McKean" 
> <users-bounces at shibboleth.net on behalf of mckeanbs at jmu.edu> wrote:
>
>> I'm trying to find a good way to force Duo use through the MFA flow 
>> within the code stanza.
>
> That's not the right spot. You control it by setting the appropriate 
> custom Principal inside the defaultAuthenticationMethods property on the 
> relying party side, and in parallel requiring signed requests or 
> blocking the RequestedAuthnContext "feature" for that SP, so that the 
> imposed requirement can't be overridden. There are examples on that in 
> the documentation.

On a related topic, can this be done for CAS services in Shibboleth?  Is 
there a way to apply an override, perhaps by groupID, for a CAS service? 
I'm not aware of any way for a CAS service to request MFA itself.

Thanks,
 	Andy


More information about the users mailing list