Logic for mfa-authn-config.xml

Karla Borecky kborecky at smith.edu
Fri Jan 12 14:39:05 EST 2018


We use Duo, and if someone is in the Duo list, they have to do MFA for any
SP - well, the first one they log into. Unless they use the 'remember me
for 30 days' thing.

On Fri, Jan 12, 2018 at 1:51 PM, Tom Scavo <trscavo at gmail.com> wrote:

> On Fri, Jan 12, 2018 at 6:13 AM, Peter Schober
> <peter.schober at univie.ac.at> wrote:
> >
> > The way I see it you can either always enforce MFA for those that have
> > it available for /all/ SPs (only requires attribute lookup) *or* you'd
> > need to implement something that enumerates the SPs for which this
> > behaviour is desired (with the IDP treating all other SPs like in
> > 1.1.).
>
> +1
>
> Tom
> --
> For Consortium Member technical support, see https://wiki.shibboleth.net/
> confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Karla Borecky
Systems Administrator
ITS
Smith College
Northampton, MA 01063


<https://content.thettp.org/educationfund>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180112/12637c03/attachment.html>


More information about the users mailing list