SSO does not work properly when using MFA
Cantor, Scott
cantor.2 at osu.edu
Mon Sep 28 12:38:25 UTC 2020
On 9/28/20, 12:54 AM, "users on behalf of Noriyuki TAKEI" <users-bounces at shibboleth.net on behalf of ntakei at sios.com> wrote:
> I'm using MFA flow which has 2 flows(password-authn-flow and TOTP Flow).The former is a built-in flow in Shibboleth
> and the latter is one which is fully developed in house based on RFC6238.
And being that it's your code, and that every single "not my code" login flow I have looked at has been implemented incorrectly (as I mentioned recently), I would imagine the problem is with your flow and that there's an error preventing the preservation of the results properly for SSO.
> I guess that reusing authentication results do not work properly.
If it does for the built-in flows and not for yours, that question answers itself.
> - idp.authn.favorSSO=true
That setting has nothing to do with this.
-- Scott
More information about the users
mailing list