MFA flow for opt-in 2FA

David Walker dwalker at internet2.edu
Fri Nov 10 10:54:09 EST 2017


Remember that, if you do that, you'll be signaling an authentication
context to the SP that it didn't ask for (and, so, may not understand).

David


On 11/10/2017 07:24 AM, Greg Haverkamp wrote:
> On Fri, Nov 10, 2017 at 7:01 AM, Liam Hoekenga <liamr at umich.edu
> <mailto:liamr at umich.edu>> wrote:
>
>     Is that something I can update?
>
>
> You'll want to edit the shibboleth.AuthenticationPrincipalWeightMap
> map in general-authn.xml to preference your MFA class.
>
> Greg
>  
>
>
>     Liam
>
>     --
>     For Consortium Member technical support, see
>     https://wiki.shibboleth.net/confluence/x/coFAAg
>     <https://wiki.shibboleth.net/confluence/x/coFAAg>
>     To unsubscribe from this list send an email to
>     users-unsubscribe at shibboleth.net
>     <mailto:users-unsubscribe at shibboleth.net>
>
>
>
>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171110/737764d6/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20171110/737764d6/attachment.sig>


More information about the users mailing list