MFA flow for opt-in 2FA

Greg Haverkamp gahaverkamp at lbl.gov
Fri Nov 10 11:15:19 EST 2017


On Fri, Nov 10, 2017 at 7:54 AM, David Walker <dwalker at internet2.edu> wrote:

> Remember that, if you do that, you'll be signaling an authentication
> context to the SP that it didn't ask for (and, so, may not understand).
>
If you do it using the weight map, you'll only be sending the SP an
authentication context class it didn't ask for if it didn't ask for one.
(If it asks for PPT, it'll still get PPT if that's one of the supported
principals.)  If the SP can't understand it, it should ask for what it
wants.

Greg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171110/e95240d9/attachment-0001.html>


More information about the users mailing list