Force authn context for IdP initiated calls
Scott Gilbert
sgilbert at ucsb.edu
Tue Oct 27 23:27:35 UTC 2020
We are using shibboleth v3.46 with shibcas plug-in v3.3.0
Is there a way to force an IDP initiated authentication and return a SAML
response for the authentication context of refeds? In other words is there
a way to configure a service provider for a specific authentication context
overriding what they request upon authentication? The IdP will always
return this authn context for this SP.
I have SP’s only requesting password authn context, Shibboleth passing it
to CAS via the plug-in, CAS enforcing 2FA sending it Duo, and Shibboleth
responding with a password authn context. The plug-in is designed to return
the authn context that was requested. I don't think I can circumvent this
even if there was a way to control at least the IdP initiated SAML
responses.
Scott Gilbert
IAM System Admin
ETS Enterprise Technology Services
University of California Santa Barbara
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20201027/2b0cbc84/attachment.htm>
More information about the users
mailing list