using ExternalAuthnConfiguration in MultiFactorAuthnConfiguration
Nate Klingenstein
ndk at sudonym.me
Thu Oct 4 07:22:57 EDT 2018
Noriyuki,
Sure, it's totally possible. You just need to have each authentication
mechanism configured and enabled(Password and whatever External
configuration you need to do for the OpenID Connect provider) and added to
the IdP's MFA map. Then, build the right logic for transitions in your
IdP's mfa-authn-config.xml file. Make certain that the canonicalized
subject names resulting from both steps match.
Take care,
Nate.
On Thu, Oct 4, 2018 at 2:14 AM, Noriyuki TAKEI <ntakei at sios.com> wrote:
> Hi,all
>
> Is it possible to use ExternalAuthnConfiguration in
> MultiFactorAuthnConfiguration?
>
> I'd like to log in to specific SP with flow as below.
>
> 1.At first,a user authenticates using ldap
>
> 2.Next, a user is redirected to OpenID Connect Provider and authenticates.
>
> 3.If authentication succeeds,a user can access to SP.
>
> --
> For Consortium Member technical support, see https://wiki.shibboleth.net/
> confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181004/dd495883/attachment.html>
More information about the users
mailing list