Logic for mfa-authn-config.xml

Paul B. Henson henson at cpp.edu
Fri Jan 12 16:15:16 EST 2018


> From: Peter Schober
> Sent: Friday, January 12, 2018 3:13 AM
> 
> AFAIU your open question is all about variant 1.2 (and variants 1.1
> and all variants for 2 are trivial), right?

I believe so.

> The way I see it you can either always enforce MFA for those that have
> it available for /all/ SPs (only requires attribute lookup)

That is not the security policy that management appears to be favoring; and I only get to implement, not define, security policy, at least for the most part :).

> Possibly giving an entity attribute to such SPs, and making the
> enforcement of MFA dependent on both the has-MFA-available attribute

That sounds like a possible place to store the categorization I need; I couldn't quite figure out from the documentation how one might add an entity attribute to an SP loaded from external metadata? Could I trouble you for an example or a pointer to the relevant documentation if I missed it?

Thanks...

--
Paul B. Henson  |  (909) 979-6361  |  http://www.cpp.edu/~henson/
Operating Systems and Network Analyst  |  henson at cpp.edu
California State Polytechnic University  |  Pomona CA 91768





More information about the users mailing list