SP Requiring/Requesting MFA (was Re: Customizing Second Factor Configuration in mfa-authn-config.xml)

Ullfig, Roberto Alfredo rullfig at uic.edu
Mon Apr 26 19:55:47 UTC 2021


Sorry, I'm not following. This configuration works - I'm not seeing where it can be subverted or why it's wrong.

---
Roberto Ullfig - rullfig at uic.edu
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Monday, April 26, 2021 2:40 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: SP Requiring/Requesting MFA (was Re: Customizing Second Factor Configuration in mfa-authn-config.xml)

On 4/26/21, 3:38 PM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces at shibboleth.net on behalf of rullfig at uic.edu> wrote:

>    We need every SP to use RemoteUser except in cases where they are forced to MFA in relying-party or they
> require MFA.

And the job of the configuration and the MFA rules is to ensure that. You can't do it by just enabling RemoteUser separately.

-- Scott


--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=04%7C01%7Crullfig%40uic.edu%7C5cdca82ba35d4de9576508d908eb322e%7Ce202cd477a564baa99e3e3b71a7c77dd%7C0%7C0%7C637550628539903018%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=gViQAOSHWSL8asrzfe1Y77V30jBEILaDLtW6HakUisA%3D&reserved=0
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210426/bb227ce7/attachment.htm>


More information about the users mailing list