Question about Shibboleth and MFA - Google Authenticator

Cantor, Scott cantor.2 at osu.edu
Fri Feb 15 12:48:55 EST 2019


> Are you referring to OATH TOTP? That's the less interesting part of Duo's
> implementation as you know. Duo pretty much invented push authentication,
> which everyone copied, and so there are lots of choices out there.

You still have to register tokens for push. Duo simply has a management process for doing that.

> Out of curiosity, are members asking about W3C WebAuthn? [1] That's where
> the authentication space seems to be headed at the moment.

No, for the same reason. WebAuthn is only usable once you register the token (the browser in this case) and have a lifecycle management story for listing them, revoking them, reporting on them, etc. That's the step that's missing from "just implement X". It's no different than any other certificate-like model. The hard work is the same no matter what the technology is.

-- Scott



More information about the users mailing list