DuoOIDC configuration IdP v4.1.0
Lipscomb, Gary
glipscomb at csu.edu.au
Thu Apr 22 01:04:25 UTC 2021
Hi list,
I'm not sure if I'm going about this the right way.
MFA using Duo works if I use authn/Duo as the nextflow.
If I change to authn/DuoOIDC I get this is not configured.
Have I missed something or is DuoOIDC not available yet.
Regards
Gary
/opt/shibboleth-idp/bin/module.sh -i idp.authn.Duo,idp.authn.MFA
Module: idp.authn.Duo
Name: Duo Authentication
Desc: Login flow for Duo Security's second-factor authentication service.
Help: https://wiki.shibboleth.net/confluence/display/IDP4/DuoAuthnConfiguration
Status: ENABLED
Resource: (noreplace) conf/authn/duo-authn-config.xml
Resource: (noreplace) conf/authn/duo.properties
Resource: (noreplace) views/duo.vm
Module: idp.authn.MFA
Name: MFA Authentication
Desc: Login flow for orchestration of multiple login methods
Help: https://wiki.shibboleth.net/confluence/display/IDP4/MultiFactorAuthnConfiguration
Status: ENABLED
Resource: (noreplace) conf/authn/mfa-authn-config.xml
2021-04-22 10:37:48,084 - - INFO [net.shibboleth.ext.spring.util.IdentifiedComponentManager:89] - Replacing auto-wired
component: authn/Duo
2021-04-22 10:37:48,085 - - INFO [net.shibboleth.ext.spring.util.IdentifiedComponentManager:89] - Replacing auto-wired
component: authn/MFA
global.xml now has
<util:list id="shibboleth.AvailableAuthenticationFlows">
<bean p:id="authn/MFA" parent="shibboleth.AuthenticationFlow"
p:order="%{idp.authn.MFA.order:1000}"
p:nonBrowserSupported="%{idp.authn.MFA.nonBrowserSupported:true}"
p:passiveAuthenticationSupported="%{idp.authn.MFA.passiveAuthenticationSupported:true}"
p:forcedAuthenticationSupported="%{idp.authn.MFA.forcedAuthenticationSupported:true}"
p:proxyRestrictionsEnforced="%{idp.authn.MFA.proxyRestrictionsEnforced:%{idp.authn.enforceProxyRestrictions:true}}"
p:proxyScopingEnforced="%{idp.authn.MFA.proxyScopingEnforced:false}"
p:discoveryRequired="%{idp.authn.MFA.discoveryRequired:false}"
p:lifetime="%{idp.authn.MFA.lifetime:%{idp.authn.defaultLifetime:PT1H}}"
p:inactivityTimeout="%{idp.authn.MFA.inactivityTimeout:%{idp.authn.defaultTimeout:PT30M}}"
p:reuseCondition-ref="#{'%{idp.authn.MFA.reuseCondition:shibboleth.Conditions.TRUE}'.trim()}"
p:activationCondition-ref="#{'%{idp.authn.MFA.activationCondition:shibboleth.Conditions.TRUE}'.trim()}">
<property name="supportedPrincipalsByString">
<bean parent="shibboleth.CommaDelimStringArray"
c:_0="#{'%{idp.authn.MFA.supportedPrincipals:}'.trim()}" />
</property>
</bean>
<bean p:id="authn/Duo" parent="shibboleth.AuthenticationFlow"
p:order="%{idp.authn.Duo.order:1000}"
p:nonBrowserSupported="%{idp.authn.Duo.nonBrowserSupported:false}"
p:passiveAuthenticationSupported="%{idp.authn.Duo.passiveAuthenticationSupported:false}"
p:forcedAuthenticationSupported="%{idp.authn.Duo.forcedAuthenticationSupported:true}"
p:proxyRestrictionsEnforced="%{idp.authn.Duo.proxyRestrictionsEnforced:%{idp.authn.enforceProxyRestrictions:true}}"
p:proxyScopingEnforced="%{idp.authn.Duo.proxyScopingEnforced:false}"
p:discoveryRequired="%{idp.authn.Duo.discoveryRequired:false}"
p:lifetime="%{idp.authn.Duo.lifetime:%{idp.authn.defaultLifetime:PT1H}}"
p:inactivityTimeout="%{idp.authn.Duo.inactivityTimeout:%{idp.authn.defaultTimeout:PT30M}}"
p:reuseCondition-ref="#{'%{idp.authn.Duo.reuseCondition:shibboleth.Conditions.TRUE}'.trim()}"
p:activationCondition-ref="#{'%{idp.authn.Duo.activationCondition:shibboleth.Conditions.TRUE}'.trim()}">
<property name="supportedPrincipalsByString">
<bean parent="shibboleth.CommaDelimStringArray"
c:_0="#{'%{idp.authn.Duo.supportedPrincipals:}'.trim()}" />
</property>
</bean>
</util:list>
mfa-authn-config.xml contains this
nextFlow = "authn/Duo";
2021-04-22 10:43:44,035 - 10.0.2.2 - WARN [DEPRECATED:132] - Spring WebFlow 'authn/Duo': This will be removed in the next major version of this software; replacement is authn/DuoOIDC
Duo web page
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Gateway to Charles Sturt University</title>
<link rel="stylesheet" type="text/css" href="view-source:https://idpdev.csu.edu.au/idp/css/main.css">
<style>
#duo_iframe {
width: 100%;
min-width: 304px;
max-width: 620px;
height: 330px;
}
</style>
</head>
Duo still uses an iframe.
If I change mfa-authn-config.xml to have
nextFlow = "authn/DuoOIDC";
I get this error
2021-04-22 10:51:40,277 - 10.0.2.2 - ERROR [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:262] - Profile Action TransitionMultiFactorAuthentication: Targeted login flow 'authn/DuoOIDC' is not configured, check available flow descriptors
Gary Lipscomb
Technical Officer, Systems(Infrastructure) | Infrastructure & Client Services | Division of Information Technology
Charles Sturt University
Panorama Avenue
Bathurst NSW 2795
Tel: +61 2 6338 6533
Email: glipscomb at csu.edu.au |www.csu.edu.au
| ALBURY-WODONGA | BATHURST | BRISBANE | CANBERRA | DUBBO | GOULBURN | MELBOURNE | ORANGE | PORT MACQUARIE | SYDNEY | WAGGA WAGGA |
LEGAL NOTICE
This email (and any attachment) is confidential and is intended for the use of the addressee(s) only. If you are not the intended recipient of this email, you must not copy, distribute, take any action in reliance on it or disclose it to anyone. Any confidentiality is not waived or lost by reason of mistaken delivery. Email should be checked for viruses and defects before opening. Charles Sturt University does not accept liability for viruses or any consequence which arise as a result of this email transmission. Email communications with Charles Sturt University may be subject to automated email filtering, which could result in the delay or deletion of a legitimate email before it is read at Charles Sturt University. The views expressed in this email are not necessarily those of Charles Sturt University.
Charles Sturt University in Australia The Grange Chancellery, Panorama Avenue, Bathurst NSW Australia 2795 (ABN: 83 878 708 551; CRICOS Provider Number: 00005F (National)). TEQSA Provider Number: PV12018
Consider the environment before printing this email.
More information about the users
mailing list