passive authn and MFA

Wessel, Keith kwessel at illinois.edu
Wed Jun 26 12:26:40 EDT 2019


Hi, all, 

For passive authn to work on an IdP, does each flow used by the authn/mfa flow need to have passive authn enabled? Or just the initial method? Seems like just the initial one would work, but I'm seeing something I don't understand here. I have passive enabled for password and MFA but not for our Duo flow. When an SP requests passive, and the user isn't logged into the SP yet, they're getting:

Status: urn:oasis:names:tc:SAML:2.0:status:Requester
Sub-Status: urn:oasis:names:tc:SAML:2.0:status:NoPassive

Does that mean the IdP can't honor passive? Or does that mean the user doesn't have an IdP session yet thus there's nothing to return?

Thanks,
Keith



More information about the users mailing list