Question about Shibboleth and MFA - Google Authenticator
Greg Haverkamp
gahaverkamp at lbl.gov
Mon Feb 18 13:23:08 EST 2019
On Sat, Feb 16, 2019 at 5:31 AM Tom Scavo <trscavo at gmail.com> wrote:
> On Fri, Feb 15, 2019 at 7:45 PM Greg Haverkamp <gahaverkamp at lbl.gov>
> wrote:
> >
> > at the time, we had to meet some NIST 800-63-2 LoA 3 requirements,
> which we could accomplish with some tweaks to LinOTP (which Duo at the time
> could not meet).
>
> OTP is not resistant to verifier impersonation so by itself it does
> not satisfy Authenticator Assurance Level 3 (as it's now called by
> NIST). Duo Push is not resistant to verifier impersonation either.
> Just saying.
Alright. But I didn’t say anything about 800-63-3, nor did I say anything
about “by itself”. (And, no, LoA 3 is not now called AAL3 if your
requirement is specifically written as being 800-63-2.)
It’s not terribly relevant to Shibboleth, anyway, as I had no requirement
to claim Shibboleth (and all of the assertion-related stuff) at LoA 3. But
I did have other systems that required authentication at LoA 3, and Duo was
insufficient. Since I’m not a Duo customer, I haven’t taken the time to
figure out where Duo Push lands these days.
Greg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190218/76fac0bc/attachment.html>
More information about the users
mailing list