Best practice MFA IdP3.3.1

Cantor, Scott cantor.2 at osu.edu
Mon Sep 11 17:45:18 EDT 2017


On 9/11/17, 5:41 PM, "users on behalf of O'Dowd, Josh" <users-bounces at shibboleth.net on behalf of Josh.O'Dowd at mso.umt.edu> wrote:

> This is kind of a tricky situation, for me anyway...  We have users who we can resolve are both employee and student, and we
> have service(s) where those users will need to choose which account they want to log in to.  Obviously, it would be best for the
> service to make this determination, but that isn't a reality in these cases.
>
> My concern is how attribute resolve will play out if one of these services comes up where there is an existing SSO session.

That's just not workable, so what I could probably say you need to do is resolve whatever "policy inputs" you need for this, and then create an interceptor that runs for the SPs needed and examines the policy data so it knows what to ask or whether to ask.

With 3.4 it will be possible to force the MFA scripts to run, but it will be awkward, I wouldn't try and do it that way when it really has nothing to do with authentication anyway.

-- Scott




More information about the users mailing list