Forcing Duo by Service Provider

Cantor, Scott cantor.2 at osu.edu
Fri Mar 31 17:49:33 EDT 2017


On 3/31/17, 5:45 PM, "users on behalf of Andrew Morgan" <users-bounces at shibboleth.net on behalf of morgan at orst.edu> wrote:

> Adding this to my scripted attribute definition worked, even when it was 
> called from the MFA flow:

You can do that, but the more "proper" form is just to populate the recipient field inside your MFA script and let the resolver just rely on it. Mainly so you don't have to worry about special casing that in every attribute script.

> It seems to be populating the entityID for CAS services too.  This example 
> above is a CAS service, and the logs contain:

Yes, as I said. It's either set or not, but it's the same for SAML or CAS.

-- Scott




More information about the users mailing list