net.shibboleth.idp.plugin.authn.duo.sdk question

Cantor, Scott cantor.2 at osu.edu
Wed Apr 7 13:11:31 UTC 2021


On 4/7/21, 9:03 AM, "users on behalf of Darren Boss" <users-bounces at shibboleth.net on behalf of darren.boss at computecanada.ca> wrote:

>    These are the plugins I have installed and I also enabled the duo plugin.

That's the *new* Duo support, not the iframe version. Assume that's clear...

I don't know exactly what the documentation says to clarify the difference between the SDK and Nimbus versions either, but our intent is that most people should really stick to the Nimbus one if they want to use the non-iframe integration, the SDK one is there mostly as a fallback if something goes wrong later with Duo's OIDC compliance.

>    There is no mfa-authn-config.xml file in conf/authn which made
>    following the instructions in the wiki confusing. Is that expected?

MFA is its own module and not enabled by default, but any upgraded system will have virtually all modules representing old features pre-enabled.

I will check to make sure the DuoOIDC documentation mentions the MFA module assuming it says anything about the MFA config at all.

 > I had Duo configured in 4.0.1 so looking at my old configuration helped
>  fill in the gaps for me.

Then you didn't upgrade because if you had, the file would be untouched and still be there.

-- Scott




More information about the users mailing list