Question about Shibboleth and MFA - Google Authenticator

Tom Scavo trscavo at gmail.com
Sat Feb 16 08:31:24 EST 2019


On Fri, Feb 15, 2019 at 7:45 PM Greg Haverkamp <gahaverkamp at lbl.gov> wrote:
>
> at the time, we had to meet some  NIST 800-63-2 LoA 3 requirements, which we could accomplish with some tweaks to LinOTP (which Duo at the time could not meet).

OTP is not resistant to verifier impersonation so by itself it does
not satisfy Authenticator Assurance Level 3 (as it's now called by
NIST). Duo Push is not resistant to verifier impersonation either.
Just saying.

Tom


More information about the users mailing list