Logic for mfa-authn-config.xml
Peter Schober
peter.schober at univie.ac.at
Thu Jan 11 11:24:01 EST 2018
* Paul B. Henson <henson at cpp.edu> [2018-01-10 22:40]:
> Applications will fall into three groups; those that do not need MFA
> at all, those that will use MFA if available but still work with
> just a password otherwise, and those that strictly require MFA and
> will fail if it does not succeed. I'm not sure yet where this
> application delineation information will be stored.
I may be restarting what Andrew and Tom already said but AFAIU that
second group of service doesn't exist: Either the service requires MFA
(and states that much in its request or in your local config) or it
doesn't (meaning it will take what it gets).
Not sure that helps (or is accurate) but maybe reducing the possible
states to two (force MFA or don't) makes this easier for you?
-peter
More information about the users
mailing list