Forcing Duo by Service Provider
Michael A Grady
mgrady at unicon.net
Fri Mar 31 17:54:38 EDT 2017
>> If you're talking routine attribute resolution, it should be set for CAS. If you're talking MFA, *you* have to set it for either SAML or CAS, or anything else, it's literally using whatever you tell it to use.
>>
>> -- Scott
>>
>
>
> We had an email chain back in mid-February on this, where it was noted that Marvin wasn't populating resolution context for CAS, and to create an Issue for that. Which I just (finally) did. From back in mid-February:
>
And I imagine it should be a separate "improvement", but I noted in the Issue I created that it would be a big bonus to make the CAS service "groupname" available in the resolver, because given the fact that CAS service urls tend to not be as "fixed" as SAML entityIDs, looking for specific values might require just looking at the URL "prefix", or a regular expression. Plus, one could ignore the CAS service URL altogether, and manage the "list of CAS services where you want the user/service 2FA calculation" by grouping, rather than by a list of URLs.
https://issues.shibboleth.net/jira/browse/IDP-1154 <https://issues.shibboleth.net/jira/browse/IDP-1154>
--
Michael A. Grady
IAM Architect, Unicon, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170331/3f67fb00/attachment.html>
More information about the users
mailing list