passive authn and MFA

Cantor, Scott cantor.2 at osu.edu
Wed Jun 26 15:02:13 EDT 2019


On 6/26/19, 12:26 PM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:

> For passive authn to work on an IdP, does each flow used by the authn/mfa flow need to have passive authn enabled?

By default, unless you override a setting that causes the MFA controller to honor the properties of the subordinate flows when it runs them to prevent accidents.

https://wiki.shibboleth.net/confluence/display/IDP30/MultiFactorAuthnConfiguration#MultiFactorAuthnConfiguration-BasicFlowValidation

shibboleth.authn.MFA.validateLoginTransitions is the bean that controls the behavior.

-- Scott




More information about the users mailing list