passive authn and MFA
Wessel, Keith
kwessel at illinois.edu
Wed Jun 26 15:23:44 EDT 2019
That's the default behavior that changed in 3.4 IIRC and the one that Andy Morgan pointed us to a few weeks back when I was asking on this list about why our step-up authn broke. So, we have changed the default. Does that mean I need to set passive supported to tru for our Duo flow for passive to work?
Keith
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Wednesday, June 26, 2019 2:02 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: passive authn and MFA
On 6/26/19, 12:26 PM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:
> For passive authn to work on an IdP, does each flow used by the authn/mfa flow need to have passive authn enabled?
By default, unless you override a setting that causes the MFA controller to honor the properties of the subordinate flows when it runs them to prevent accidents.
https://wiki.shibboleth.net/confluence/display/IDP30/MultiFactorAuthnConfiguration#MultiFactorAuthnConfiguration-BasicFlowValidation
shibboleth.authn.MFA.validateLoginTransitions is the bean that controls the behavior.
-- Scott
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list