Forcing Duo by Service Provider
Cantor, Scott
cantor.2 at osu.edu
Fri Mar 31 17:49:33 EDT 2017
On 3/31/17, 5:45 PM, "users on behalf of Andrew Morgan" <users-bounces at shibboleth.net on behalf of morgan at orst.edu> wrote:
> Adding this to my scripted attribute definition worked, even when it was
> called from the MFA flow:
You can do that, but the more "proper" form is just to populate the recipient field inside your MFA script and let the resolver just rely on it. Mainly so you don't have to worry about special casing that in every attribute script.
> It seems to be populating the entityID for CAS services too. This example
> above is a CAS service, and the logs contain:
Yes, as I said. It's either set or not, but it's the same for SAML or CAS.
-- Scott
More information about the users
mailing list