Shibboleth Native MFA/Duo integration questions.
Jeffrey Crawford
jeffreyc at ucsc.edu
Thu Sep 21 14:43:21 EDT 2017
Sorry for the length of this. I'll try and be as terse as possible
We are starting to look at implementing Duo MFA (Again). I've been reading
the documentation and I think I understand the simple implementation,
however what we are proposing to do is bring up some high level questions.
An admittingly sledgehammer approach is that we are proposing we perform
MFA on every site, however we configure duo to allow bypass if they are not
enrolled. That means if you have a duo profile you will be prompted for MFA
if the SP doesn't make a specific context ref request. In addition we want
to allow users to save their device for some amount of days yet to be
defined. I'm not too worried about that one because the SP probably doesn't
care if MFA was performed or not.
However in looking at the refeeds.org/mfa there would undoubtedly be SPs
that are interested in the fact an MFA challenge was made. However I'm not
sure how that works technically. If MFA is presented and the user does not
have a profile, then it may still go through the duo workflow but no MFA is
actually performed. It looks like the default way to handle this is to
assert that AuthenContextRef is mfa, BUT for someone who doesn't have a
profile we shouldn't do that, or did I miss some callback that does define
that?
Additionally if a device is saved, is that enough to assert MFA? I could
see it falling into "something you have" as opposed to "something you do".
Obviously "something you do" comes first.
The last point is if we do default MFA (where SP doesn't care) and we have
the MFA context request does that require different polices do we therefore
need multiple duo integrations?
Jeffrey E. Crawford
Enterprise Service Team <jeffreyc at ucsc.edu>
^ ^
/ \ ^ / \ ^
/ \/ \ / \ / \
/ \/ \/ \
/ \
You have been assigned this mountain to prove to others that it *can* be
moved.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170921/f97411f6/attachment.html>
More information about the users
mailing list