SP Requiring/Requesting MFA (was Re: Customizing Second Factor Configuration in mfa-authn-config.xml)
Ullfig, Roberto Alfredo
rullfig at uic.edu
Mon Apr 26 14:51:50 UTC 2021
I found that one of our service providers works with an IDP that doesn't support MFA - yet when I enable MFA support, logins to the SP execute the MFA flow. If the SP required it shouldn't it have failed before?
---
Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Thursday, April 22, 2021 3:22 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: Customizing Second Factor Configuration in mfa-authn-config.xml
> I noticed that this code allows MFA from the NIH Security Compliance tool
> (without any further configuration on our end in relying-party) - I assume that's
> because the tool requests (requires?) MFA?
It does, yes.
> Can these MFA requests sent by the SP be optional or is an MFA request always
> a mandatory requirement?
What is requested is mandatory. Whether that's MFA alone or not depends on what's requested.
-- Scott
--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Crullfig%40uic.edu%7Cb6bafdf4c7744f1caf7808d905cc6a75%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637547197790515667%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=JyXHKrh7qG3QS4FUpxpS4stDPZ0DoeZ7Z6Ri8ZKxNOM%3D&reserved=0
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210426/885fb3ff/attachment.htm>
More information about the users
mailing list