[External]Re: Shibboleth with Azure AD and handling REFEDS MFA compliance

Daniels, John DANIELSJ1 at chop.edu
Wed Jun 16 15:05:13 UTC 2021


That’s what I was thinking.
To be clear about 4.0/4.1. We run the IDP from a container and add in the files we need to overwrite to configure. We did originally build our container on 4.0 and later rebased the Dockerfile to use 4.1. But authn-general.xml was never a file we managed, we let the base image populate it. Now that we’ve moved to 4.1, it’s not there:
 
Running IDP:
[root at 6e1304c46c60 authn]# ls -l
-rw-r--r--. 1 root root 3586 Jun 16 12:33 authn-comparison.xml
-rw-r--r--. 1 root root  856 Mar 24 15:54 authn-events-flow.xml
-rw-r--r--. 1 root root 8874 Jun 16 12:33 authn.properties
-rw-r--r--. 1 root root 6457 Mar 24 15:54 password-authn-config.xml
-rw-r--r--. 1 root root 1849 Jun 16 12:33 saml-authn-config.xml
 
 
Is there another file from 4.0 we may have maintained that might impact this? Or is it just that authn-general.xml?
 
Thanks,
John
 
--
John Daniels
Principal Systems Engineer
Children's Hospital of Philadelphia Research Institute
 
 

On 6/16/21, 10:58 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

    On 6/16/21, 10:51 AM, "Daniels, John" <DANIELSJ1 at chop.edu> wrote:
    
    >    4.1 to start, I don't have a general-authn.xml.
    
    Then I can't explain it, that error isn't possible. A 4.1 install would auto-load authn.properties, and that's all it would take if the only login flow enabled is "SAML". It can't be claiming there's no flow supporting the request in that situation. So there are facts not in evidence somewhere.
    
    -- Scott
    
    
    ** This email originated from an EXTERNAL sender to CHOP. Proceed with caution when replying, opening attachments, or clicking links. Do not disclose your CHOP credentials, employee information, or protected health information to a potential hacker**.
    



More information about the users mailing list