Failmode of Duo Authentication Flow
Christopher Bongaarts
cab at umn.edu
Fri Jan 31 16:12:45 EST 2020
One way is to use a host or network firewall to temporarily block
traffic to your Duo API host's IP.
On 1/31/2020 3:00 PM, Zunan Dong wrote:
>
> Thanks David, this explains it. Is there anyway that we can test it?
>
> Zunan
>
>
> On 2020-01-31 03:27 PM, IAM David Bantz wrote:
>> Presumably the idp.duo.failmode is triggered on inability to connect
>> to Duo, not on Duo receiving a request referencing an invalid
>> integration.
>>
>> On Fri, Jan 31, 2020 at 11:13 AM Zunan Dong <zunan.dong at utoronto.ca
>> <mailto:zunan.dong at utoronto.ca>> wrote:
>>
>> Hi Lee,
>>
>> I have put idp.duo.failmode=safe along with a wrong secretKey in
>> duo.properties file. When I login, I pass the primary
>> authn(Username/Password), it shows me an error page afterwards. I
>> also tried to put in a wrong apiHost, which gives me an error in
>> the Duo iframe. I guess this doesn't work for me.
>>
>> Zunan
>>
>> On 2020-01-31 02:19 PM, Lee Foltz wrote:
>>> This is outlined here below and and example of what we use. We
>>> are running IDP 3.4.6
>>> https://wiki.shibboleth.net/confluence/pages/viewpage.action?pageId=32112643
>>>
>>>
>>> Configured in duo.properties
>>> idp.duo.failmode = safe
>>> idp.duo.failmode = secure
>>>
>>> safe mode - In the event that Duo's service cannot be contacted,
>>> users' authentication attempts will be permitted if primary
>>> authentication succeeds. (Default)
>>> secure mode - In the event that Duo's service cannot be
>>> contacted, all users' authentication attempts will be rejected.
>>>
>>> On Fri, Jan 31, 2020 at 2:05 PM Zunan Dong
>>> <zunan.dong at utoronto.ca <mailto:zunan.dong at utoronto.ca>> wrote:
>>>
>>> Hi Team,
>>>
>>> Our organization is trying to integrate Duo with Shibboleth IdP.
>>>
>>> We're trying configuring the failmode of Duo authentication
>>> flow. It
>>> seems like that Duo provides an optional parameter,
>>> "duo.failmode",
>>> which should be configurable in duo.properties file.
>>> However, I don't
>>> see any comments in duo.properties file for this parameter.
>>> And also,
>>> there is no "failmode" field in the
>>> "net.shibboleth.idp.authn.duo.BasicDuoIntegration" class.
>>> I'm wondering
>>> if there is a way to set the failmode of Duo authentication?
>>> The version
>>> of our current IdP is V3.3. Any suggestion would be helpful.
>>>
>>> Appreciated,
>>>
>>> --
>>> Zunan Dong
>>> Authentication Systems Specialist
>>> Information Security
>>> Information Technology Services
>>> University of Toronto
>>> Email: zunan.dong at utoronto.ca <mailto:zunan.dong at utoronto.ca>
>>>
>>> --
>>> For Consortium Member technical support, see
>>> https://wiki.shibboleth.net/confluence/x/coFAAg
>>> <https://wiki.shibboleth.net/confluence/x/coFAAg>
>>> To unsubscribe from this list send an email to
>>> users-unsubscribe at shibboleth.net
>>> <mailto:users-unsubscribe at shibboleth.net>
>>>
>>>
>>>
>>> --
>>> Lee Foltz
>>> Oakland University - UTS
>>> Senior Identity and Access Management Engineer
>>> 248-370-2675
>>>
>>>
>>
>> --
>> Zunan Dong
>> Authentication Systems Specialist
>> Information Security
>> Information Technology Services
>> University of Toronto
>> Email:zunan.dong at utoronto.ca <mailto:zunan.dong at utoronto.ca>
>>
>> --
>> For Consortium Member technical support, see
>> https://wiki.shibboleth.net/confluence/x/coFAAg
>> <https://wiki.shibboleth.net/confluence/x/coFAAg>
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>> <mailto:users-unsubscribe at shibboleth.net>
>>
>>
>>
>
> --
> Zunan Dong
> Authentication Systems Specialist
> Information Security
> Information Technology Services
> University of Toronto
> Email:zunan.dong at utoronto.ca
>
>
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200131/d68733c5/attachment.html>
More information about the users
mailing list