Forcing Duo by Service Provider
Cantor, Scott
cantor.2 at osu.edu
Fri Mar 31 17:59:47 EDT 2017
As I noted in the bug, I'm 95% certain it can't be failing to set the ID. If I had a simple way to check I would. I'm pretty sure the confusion here is between normal resolution and the MFA flow doing it. That's a very different case.
> On 3/31/17, 5:54 PM, "users on behalf of Michael A Grady" <users-bounces at shibboleth.net on behalf of mgrady at unicon.net
>wrote:
>
>And I imagine it should be a separate "improvement", but I noted in the Issue I created that it would be a big bonus to make the
> CAS service "groupname" available in the resolver, because given the fact that CAS service urls tend to not be as "fixed" as
> SAML entityIDs, looking for specific values might require just looking at the URL "prefix", or a regular expression. Plus, one could
> ignore the CAS service URL altogether, and manage the "list of CAS services where you want the user/service 2FA calculation"
> by grouping, rather than by a list of URLs.
It is available in the resolver, as I noted when asked, so I assume you mean "accessed more easily".
-- Scott
More information about the users
mailing list