SP Requiring/Requesting MFA (was Re: Customizing Second Factor Configuration in mfa-authn-config.xml)

Cantor, Scott cantor.2 at osu.edu
Mon Apr 26 20:30:56 UTC 2021


On 4/26/21, 3:55 PM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces at shibboleth.net on behalf of rullfig at uic.edu> wrote:

>    Sorry, I'm not following. This configuration works - I'm not seeing where it can be subverted or why it's
> wrong.

I can't explain that without trying to explain all of the internals. It has to do with how the results are tracked. At minimum it will result in extra round trips through the RemoteUser step because the cases where it runs alone will not be "reused" when the MFA flow routes to it.

In simple cases where the first factor flow is enabled in both places it's not going to have much more impact than limiting SSO (*). If a second factor flow were enabled also or instead, it would just outright break in some cases.

-- Scott

(*) Which may be practically invisible to users anyway if the RemoteUser method itself is already handling SSO for that factor, which is common. Using Password is a more obvious example because there will be unexpected prompts for the password.




More information about the users mailing list