Logic for mfa-authn-config.xml

Tom Scavo trscavo at gmail.com
Fri Jan 12 13:51:59 EST 2018


On Fri, Jan 12, 2018 at 6:13 AM, Peter Schober
<peter.schober at univie.ac.at> wrote:
>
> The way I see it you can either always enforce MFA for those that have
> it available for /all/ SPs (only requires attribute lookup) *or* you'd
> need to implement something that enumerates the SPs for which this
> behaviour is desired (with the IDP treating all other SPs like in
> 1.1.).

+1

Tom


More information about the users mailing list