Multiple authentication levels for a single application

Guillaume Rousse guillaume.rousse at renater.fr
Tue Aug 27 11:44:01 EDT 2019


Le 27/08/2019 à 16:59, Morgan, Andrew Jason a écrit :
> I haven't looked recently, but the InCommon certificate service app (run 
> by Comodo) used the following methodology:
> 
>  1. Send an authnRequest with no authnContextClassRef (or was it
>     PasswordProtectedTransport?)
>  2. After successful auth, lookup the user to see if MFA is required for
>     this user
>  3. If MFA is required for that user, send another authnRequest with the
>     authnContextClassRef set to https://refeds.org/profile/mfa
> 
> This allows the application to decide if MFA is required, and it uses 
> SSO to avoid prompting the user for their password twice.
That seems great.

I didn't considered the possibility for an application to chain multiple 
authentication requests. Is there any documentation available somewhere 
about how to implement this  ?

Regards.
-- 
Guillaume Rousse
Pôle SSI

Tel: +33 1 53 94 20 45
www.renater.fr

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3637 bytes
Desc: Signature cryptographique S/MIME
URL: <http://shibboleth.net/pipermail/users/attachments/20190827/ec604d90/attachment.p7s>


More information about the users mailing list