Logic for mfa-authn-config.xml

Paul B. Henson henson at cpp.edu
Thu Jan 11 21:44:34 EST 2018


> From: David Walker
> Sent: Thursday, January 11, 2018 9:00 AM
> 
> The second group would be applications that tailor the access they provide
> based on the type of authentication performed, perhaps later requesting
> (and requiring) MFA when sensitive/risky transactions are attempted.

Well, actually, in my classification that is a completely new category I hadn't even considered yet 8-/. Although doesn't that just work out-of-the-box; initially the application asserts a password context and then later forces a reauth requiring an MFA context?

My second group are applications that once you authenticate successfully you get to use without any future context changes, but that will do MFA if a user can but not fail if they can't.

Thanks…

--
Paul B. Henson  |  (909) 979-6361  |  http://www.cpp.edu/~henson/
Operating Systems and Network Analyst  |  henson at cpp.edu
California State Polytechnic University  |  Pomona CA 91768





More information about the users mailing list