Logic for mfa-authn-config.xml

Paul B. Henson henson at cpp.edu
Fri Jan 12 16:02:45 EST 2018


> From: Cantor, Scott
> Sent: Thursday, January 11, 2018 6:52 PM
> 
> How would you expect the IdP to distinguish these unless you can articulate
> a rule? If you can, then that answers the question you're asking, that's the
> rule.

Sorry, perhaps I'm being stupid; but there is a difference between "it is possible to articulate a rule", and "I know how to do so". My hope from this thread was to figure out how to best articulate said rule :).

> - the ones that require MFA and can't ask, which I enumerate with a relying
> party rule

Here, do you mean in the MFA selection logic, or by overriding the desired authentication context for the entity-id?

> - the ones that "require MFA sort of except for when they don't", which
> involve both enumerating services and combining it with an attribute lookup
> on the user

That sounds like what I'm looking to do, and am just trying to sort out the best way of doing so.

> All of that is fairly obvious to implement, using a couple of different relying
> party overides and some user attribute checks.

Well, obvious to <expert developer with insane amounts of knowledge> compared to <mostly end-user who occasionally pokes at code or needs a more complex than usual configuration> aren't quite the same ;). Thanks for the input, and sorry if I'm asking silly questions :).

--
Paul B. Henson  |  (909) 979-6361  |  http://www.cpp.edu/~henson/
Operating Systems and Network Analyst  |  henson at cpp.edu
California State Polytechnic University  |  Pomona CA 91768





More information about the users mailing list