Multiple authentication levels for a single application
Guillaume Rousse
guillaume.rousse at renater.fr
Tue Aug 27 11:44:01 EDT 2019
Le 27/08/2019 à 16:59, Morgan, Andrew Jason a écrit :
> I haven't looked recently, but the InCommon certificate service app (run
> by Comodo) used the following methodology:
>
> 1. Send an authnRequest with no authnContextClassRef (or was it
> PasswordProtectedTransport?)
> 2. After successful auth, lookup the user to see if MFA is required for
> this user
> 3. If MFA is required for that user, send another authnRequest with the
> authnContextClassRef set to https://refeds.org/profile/mfa
>
> This allows the application to decide if MFA is required, and it uses
> SSO to avoid prompting the user for their password twice.
That seems great.
I didn't considered the possibility for an application to chain multiple
authentication requests. Is there any documentation available somewhere
about how to implement this ?
Regards.
--
Guillaume Rousse
Pôle SSI
Tel: +33 1 53 94 20 45
www.renater.fr
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3637 bytes
Desc: Signature cryptographique S/MIME
URL: <http://shibboleth.net/pipermail/users/attachments/20190827/ec604d90/attachment.p7s>
More information about the users
mailing list