Question about Shibboleth and MFA - Google Authenticator
Tom Scavo
trscavo at gmail.com
Sat Feb 16 08:31:24 EST 2019
On Fri, Feb 15, 2019 at 7:45 PM Greg Haverkamp <gahaverkamp at lbl.gov> wrote:
>
> at the time, we had to meet some NIST 800-63-2 LoA 3 requirements, which we could accomplish with some tweaks to LinOTP (which Duo at the time could not meet).
OTP is not resistant to verifier impersonation so by itself it does
not satisfy Authenticator Assurance Level 3 (as it's now called by
NIST). Duo Push is not resistant to verifier impersonation either.
Just saying.
Tom
More information about the users
mailing list