net.shibboleth.idp.plugin.authn.duo.sdk question

Darren Boss darren.boss at computecanada.ca
Wed Apr 7 13:35:58 UTC 2021


On Wed, Apr 7, 2021 at 9:11 AM Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> On 4/7/21, 9:03 AM, "users on behalf of Darren Boss" <users-bounces at shibboleth.net on behalf of darren.boss at computecanada.ca> wrote:
>
> >    These are the plugins I have installed and I also enabled the duo plugin.
>
> That's the *new* Duo support, not the iframe version. Assume that's clear...
Yes, that's clear and it's working, full redirect with the
net.shibboleth.idp.plugin.authn.duo.sdk plugin, no iframe.

> I don't know exactly what the documentation says to clarify the difference between the SDK and Nimbus versions either, but our intent is that most people should really stick to the Nimbus one if they want to use the non-iframe integration, the SDK one is there mostly as a fallback if something goes wrong later with Duo's OIDC compliance.
Ok, I'll take that as a strong suggestion to use the Numbus plugin.
The docs were not very opinionated in which plugin was recommended.

> >    There is no mfa-authn-config.xml file in conf/authn which made
> >    following the instructions in the wiki confusing. Is that expected?
>
> MFA is its own module and not enabled by default, but any upgraded system will have virtually all modules representing old features pre-enabled.
I didn't upgrade, I'm basically doing a new install. Thanks for the
clarification, I'm reading the 4.1+ section of the MFA docs now and
the new module commands are starting to sink in. Do all module enable
commands just copy files or can they be more sophisticated than that
like actually modify an existing file? Is their a list and description
of all the modules that can be enabled?

> I will check to make sure the DuoOIDC documentation mentions the MFA module assuming it says anything about the MFA config at all.
>
>  > I had Duo configured in 4.0.1 so looking at my old configuration helped
> >  fill in the gaps for me.
>
> Then you didn't upgrade because if you had, the file would be untouched and still be there.
Correct, basically doing a new install. What I actually have is a new
install with the plugins I want and now I'm more aware of the module
commands, I will run those in the new install. I then compare to a
checked out git repository which has all the versioned configuration.
I use a tool to compare and manually merge the new file with my older
configuration. I'm fully aware that this is far from the easiest way
to go from 4.0.1 to 4.1.0. When the IdP comes up, the conf directory
structure is completely overlayed from the git repo on top of the conf
structure in the Docker image while secrets get overlayed from another
source.

Just to be clear, it appears as if everything is working for me. I'm
just trying to clear up some of my confusion and hopefully other
people's as well on the upgrade and I'm already glad I posted my
inquiries here.
-- 
Darren Boss
Senior Programmer/Analyst
Programmeur-analyste principal
darren.boss at computecanada.ca


More information about the users mailing list