Forcing Duo by Service Provider
Andrew Morgan
morgan at orst.edu
Wed Mar 29 20:29:34 EDT 2017
On Wed, 29 Mar 2017, Cantor, Scott wrote:
> On 3/29/17, 11:56 AM, "users on behalf of Brandon McKean"
> <users-bounces at shibboleth.net on behalf of mckeanbs at jmu.edu> wrote:
>
>> I'm trying to find a good way to force Duo use through the MFA flow
>> within the code stanza.
>
> That's not the right spot. You control it by setting the appropriate
> custom Principal inside the defaultAuthenticationMethods property on the
> relying party side, and in parallel requiring signed requests or
> blocking the RequestedAuthnContext "feature" for that SP, so that the
> imposed requirement can't be overridden. There are examples on that in
> the documentation.
On a related topic, can this be done for CAS services in Shibboleth? Is
there a way to apply an override, perhaps by groupID, for a CAS service?
I'm not aware of any way for a CAS service to request MFA itself.
Thanks,
Andy
More information about the users
mailing list