SAML - confirm MFA auth

Cantor, Scott cantor.2 at osu.edu
Thu Jul 8 19:09:58 UTC 2021


On 7/8/21, 2:08 PM, "users on behalf of Ilya Rumyantsev" <users-bounces at shibboleth.net on behalf of iliggio at gmx.de> wrote:

>    How would we configure shibboleth IDP in a way that it confirms to the SPs (in the assertion) that a 2-Factor
> auth has taken place?

The supportedPrincipals property associated with login flows determines what AuthnContextClassRef values are associated with requests and responses, the documentation covers it at length.

The specifics vary by version now because of the changes in 4.1 to simplify configuration.

-- Scott




More information about the users mailing list