No attributes after enabling MFA flow

Paul B. Henson henson at cpp.edu
Wed May 16 23:34:42 EDT 2018


So I went to deploy Duo MFA in production for a limited pilot group, but had to rapidly back it out after I discovered attributes were not being passed to SAML service providers 8-/. CAS protocol based services seemed to be fine, but accessing a SAML service using the MFA flow resulted in no attributes:

2018-05-16 20:02:23,498 - 20180517T030223Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_6f429c5972ac26ee63ab40e1c361c8c7|https://shib.lynda.com/shibboleth-sp|http://shibboleth.net/ns/profiles/saml2/sso/browser|https://idp.cpp.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_bbeba5abde9eb665ef11148534fe4cf2|henson|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|||_ab6c54c29f3412dc20be258376caa86e|

Changing the idp.authn.flows parameter back to "Password", attributes returned:

2018-05-16 20:11:33,420 - 20180517T031133Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_85c62aff0ad5135125d2b40cc1940c8f|https://shib.lynda.com/shibboleth-sp|http://shibboleth.net/ns/profiles/saml2/sso/browser|https://idp.cpp.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_0551f270209c95c535a8983cca707944|henson|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|eduPersonEntitlement,mail,eduPersonAffiliation,givenName,calstateEduPersonEmplID,sn,cn|aYcr2tew+mg5Jkun1J6L2xUCZZY=|_851178db5423ad267cc91808da667b3b|

I'm going to call it a night and revisit this in the morning, but any thoughts on what might be going on here? I don't know if it's relevant, but I'm using a custom version of 3.3.3 with IDP-1114 back ported; I'll try the stock version tomorrow and see if that makes a difference.

Thanks...

--
Paul B. Henson  |  (909) 979-6361  |  http://www.cpp.edu/~henson/
Operating Systems and Network Analyst  |  henson at cpp.edu
California State Polytechnic University  |  Pomona CA 91768




More information about the users mailing list