Multiple authentication levels for a single application

Guillaume Rousse guillaume.rousse at renater.fr
Tue Aug 27 10:55:58 EDT 2019


Le 27/08/2019 à 14:18, Losen, Stephen C (scl) a écrit :
> Hi Guillaume,
> 
> Your final suggestion, always using the MFA flow and configuring it to conditionally trigger the second factor, is what we do. We use user attributes in LDAP to control this. The MFA flow can retrieve attributes from LDAP after the first factor (password) and conditionally trigger the second factor. The Shib IDP wiki has examples.
> 
> You could have a "MFA-required" group where members trigger the second factor while non-members do not.
In this scenario, with multiple potential results for a given flow, is 
there any need for the SP to express a requirement in its authentication 
request (as one or multiple authnContextClassRef values), or is it 
useless, as the IdP only know about a single flow anyway ?

Regards.
-- 
Guillaume Rousse
Pôle SSI

Tel: +33 1 53 94 20 45
www.renater.fr

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3637 bytes
Desc: Signature cryptographique S/MIME
URL: <http://shibboleth.net/pipermail/users/attachments/20190827/4077462b/attachment.p7s>


More information about the users mailing list