Logic for mfa-authn-config.xml

Paul B. Henson henson at cpp.edu
Fri Jan 12 16:21:36 EST 2018


> From: Andrew Morgan
> Sent: Friday, January 12, 2018 9:34 AM
>
> I was too lazy to give you my own MFA logic originally...  :)

Laziness is a system administrator's best friend ;).

> This MFA logic starts by asking if the previous authentication method

Thanks for the example, that's very helpful. The one case it doesn't cover though I think is where the SP doesn't require MFA, the user has MFA available, but management has made an executive decision that that particular application should not ask for MFA? To deal with that third state, I think I need to tag SP's with an attribute as well as users.

Thanks again...


More information about the users mailing list