passive authn and MFA

Wessel, Keith kwessel at illinois.edu
Wed Jun 26 15:23:44 EDT 2019


That's the default behavior that changed in 3.4 IIRC and the one that Andy Morgan pointed us to a few weeks back when I was asking on this list about why our step-up authn broke. So, we have changed the default. Does that mean I need to set passive supported to tru for our Duo flow for passive to work?

Keith


-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Wednesday, June 26, 2019 2:02 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: passive authn and MFA

On 6/26/19, 12:26 PM, "users on behalf of Wessel, Keith" <users-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:

> For passive authn to work on an IdP, does each flow used by the authn/mfa flow need to have passive authn enabled?

By default, unless you override a setting that causes the MFA controller to honor the properties of the subordinate flows when it runs them to prevent accidents.

https://wiki.shibboleth.net/confluence/display/IDP30/MultiFactorAuthnConfiguration#MultiFactorAuthnConfiguration-BasicFlowValidation

shibboleth.authn.MFA.validateLoginTransitions is the bean that controls the behavior.

-- Scott


-- 
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list