passive authn and MFA
Cantor, Scott
cantor.2 at osu.edu
Wed Jun 26 15:02:13 EDT 2019
On 6/26/19, 12:26 PM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:
> For passive authn to work on an IdP, does each flow used by the authn/mfa flow need to have passive authn enabled?
By default, unless you override a setting that causes the MFA controller to honor the properties of the subordinate flows when it runs them to prevent accidents.
https://wiki.shibboleth.net/confluence/display/IDP30/MultiFactorAuthnConfiguration#MultiFactorAuthnConfiguration-BasicFlowValidation
shibboleth.authn.MFA.validateLoginTransitions is the bean that controls the behavior.
-- Scott
More information about the users
mailing list