Logic for mfa-authn-config.xml
Paul B. Henson
henson at cpp.edu
Thu Jan 11 21:46:38 EST 2018
> From: Les LaCroix
> Sent: Thursday, January 11, 2018 9:18 AM
>
> Use case: application X has some users with elevated access internally (the
> application admins). By convention all those application administrators have
> mfa available to them. They still want people without mfa to access the
> application, because that's its main use.. But if you have mfa available for
> some other reason, it's not a bad thing for you to have your session mfa-
> protected. It's just not relevant to the application.
Yes, that exactly :).
In our case, all faculty and staff will have MFA available, but possibly not students depending on cost and certainly not applicants, who also have accounts and need to access some of the same services as everybody else.
--
Paul B. Henson | (909) 979-6361 | http://www.cpp.edu/~henson/
Operating Systems and Network Analyst | henson at cpp.edu
California State Polytechnic University | Pomona CA 91768
More information about the users
mailing list