IDPv3 with ADFSv3 proxy
Cantor, Scott
cantor.2 at osu.edu
Fri Aug 16 10:03:46 EDT 2019
On 8/16/19, 9:55 AM, "users on behalf of Christopher Bland" <users-bounces at shibboleth.net on behalf of chris at fdu.edu> wrote:
> Forget to ask for clarity, my approach of ignoring the context won't work?
I don't believe violating the standard is an apropriate thing to do, but the IdP doesn't impose those value judgements on everybody else.
> Thanks for the quick response. While I need to fix this as quickly as possible, I want figure out what the best practice
> is. I quoted you because in the old post you basically said they were bad approaches and I wanted readers to know they
> had been looked at.
I don't recall ever having much to say about anybody's AuthnContext classes. I don't think adding synonyms for "Password" is all that big a deal, but whether I would do it just depends on how much leverage I had. Nobody's changing what Office apps do, so there's not much leverage.
> Is redeclaring and overriding the supported classes what you did at OSU?
I have never had to do anything about it, it's never come up. I'm not involved in the Office365 work so I imagine that's why.
What I would *not* do is artifically compensate for an application that requests Password authentication when it comes to my MFA logic. If you ask for Password, that's what you get. If you want MFA, you stop asking for Password.
An application asking for Password authentication doesn't know what it's doing or why, and has a bug. So the first step is to file a bug anyway.
-- Scott
More information about the users
mailing list