ECP on an idp configured for MFA

Paul B. Henson henson at cpp.edu
Tue Feb 19 16:48:57 EST 2019


I thought I had ECP configured correctly, but I don't believe we have ever used it. A use case has come up, but when testing, it fails, with the following errors in the logs:

> 2019-02-19 12:32:00,693 - 2620:df:8000:f000:0:1:250:134/8CA499659F924C5A4A5298EC2DB03FCD - WARN [net.shibbolet
> h.idp.profile.impl.SelectProfileConfiguration:117] - Profile Action SelectProfileConfiguration: Profile http:/
> /shibboleth.net/ns/profiles/saml2/sso/ecp is not available for RP configuration RelyingPartyByTag$child#6ccca5
> 57 (RPID https://cilogon.org/shibboleth)
> 2019-02-19 12:32:00,698 - 2620:df:8000:f000:0:1:250:134/8CA499659F924C5A4A5298EC2DB03FCD - WARN [org.opensaml.
> profile.action.impl.LogEvent:105] - A non-proceed event occurred while processing the request: InvalidProfileConfiguration

It looks like in order for it to work, you need to include the Password flow:

https://wiki.shibboleth.net/confluence/display/IDP30/ECPConfiguration

However, we are doing MFA, and per that configuration recommendation:

https://wiki.shibboleth.net/confluence/display/IDP30/MultiFactorAuthnConfiguration

MFA should be the only flow enabled. The warning "because to do so would cause the IdP to run them itself in ways that are likely to subvert your intent" regarding enabling other flows makes me leery of adding back password for the sake of ECP.

What is the recommended configuration for an idp that is using MFA to also support ECP?

Thanks...

--
Paul B. Henson  |  (909) 979-6361  |  http://www.cpp.edu/~henson/
Operating Systems and Network Analyst  |  henson at cpp.edu
California State Polytechnic University  |  Pomona CA 91768




More information about the users mailing list