[Ext] Re: Forcing Duo by Service Provider

Cantor, Scott cantor.2 at osu.edu
Fri Mar 31 20:04:27 EDT 2017


On 3/31/17, 6:51 PM, "users on behalf of Bryan Wooten" <users-bounces at shibboleth.net on behalf of bryan.wooten at utah.edu> wrote:

> No. Via the Duo Admin Console we have set ³deny un-enrolled users².

I'm just describing the decisions which will make deployment more painful. Any per-user policy will be tougher, no matter what it is. Possibly I just lack the imagination or skill to build a system that accomodates it well, but it's about as good as it's going to get.

> Since our IDP defers to CAS for authn it is simple, if your employment
> status is ³current² (per LDAP) you will use MFA.

Has nothing to do with CAS. Whether you use RemoteUser or Password or anything else, the issue is that you are impacting the IdP's usual expectation of ordering by needing to resolve attributes before or during its authentication logic. It took 4 tries to get it to a state where that isn't horrendous and full of bugs, and it's still not all that easy, just easier and at least somewhat predictable.

> Whether I am in the office or at home it takes me 3-4 Duo pushes to get
> into the systems I need to resolve a tier 3 help ticket.

Yikes!

-- Scott




More information about the users mailing list