Logic for mfa-authn-config.xml
Paul B. Henson
henson at cpp.edu
Thu Jan 11 21:35:00 EST 2018
> From: Andrew Morgan
> Sent: Wednesday, January 10, 2018 2:39 PM
>
> The signal to the IDP that MFA is required is the authnContextClassRef.
> This can be sent in the SAML request by the SP or hard-coded in
> relying-party.xml on the IDP.
Unless I'm mistaken, this operates under the assumption that an application either doesn't use MFA or must use MFA, which will not satisfy the category of opportunistic use? There is a set of applications which will not fail without MFA for users that do not have it available, but should not allow users that do have MFA available to access them without it.
> You can also detect the SP entityID in your MFA logic and switch Duo on
> programmatically in the MFA script. In my opinion, that is needlessly
> complex.
Hmm, I guess that is a worst-case scenario if I can't find anything else to do.
Thanks...
--
Paul B. Henson | (909) 979-6361 | http://www.cpp.edu/~henson/
Operating Systems and Network Analyst | henson at cpp.edu
California State Polytechnic University | Pomona CA 91768
More information about the users
mailing list