SP Requiring/Requesting MFA (was Re: Customizing Second Factor Configuration in mfa-authn-config.xml)
Cantor, Scott
cantor.2 at osu.edu
Mon Apr 26 19:39:32 UTC 2021
On 4/26/21, 3:32 PM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces at shibboleth.net on behalf of rullfig at uic.edu> wrote:
> The original example uses IPAddress and Password and there's mention of replacing this with Password and
> Duo - why would we not use RemoteUser and Duo then?
You would, but the documentation also has a big green tip box with:
"Note that when you use the MFA flow, it's common that it will be the only flow enabled via the idp.authn.flows property. In particular, any flows you direct the MFA flow to run via rules and scripts should not be enabled themselves because to do so may cause the IdP to run them itself in ways that are likely to subvert your intent."
The only case in which the MFA flow wouldn't be the only one enabled in the property would be if you were doing authentication with SPNEGO or X.509 or something similar and driving that separately from the MFA scripting logic.
-- Scott
More information about the users
mailing list