Shibboleth Native MFA/Duo integration questions.
Cantor, Scott
cantor.2 at osu.edu
Mon Sep 25 09:33:24 EDT 2017
On 9/21/17, 2:43 PM, "users on behalf of Jeffrey Crawford" <users-bounces at shibboleth.net on behalf of jeffreyc at ucsc.edu> wrote:
> Additionally if a device is saved, is that enough to assert MFA? I could see it falling into "something you
> have" as opposed to "something you do". Obviously "something you do" comes first.
This is a subjective question. I don't believe it's MFA, lots of other people do. The REFEDS/InCommon profile says it is.
Duo's "simple" iframe approach to doing the MFA doesn't tell the IdP enough for it to make a distinction, so it will assume MFA and assert that anyway, which happens to fit the profile.
> The last point is if we do default MFA (where SP doesn't care) and we have the MFA context request does
> that require different polices do we therefore need multiple duo integrations?
Shouldn't.
-- Scott
More information about the users
mailing list