Multiple 2FA mechanism in Shibboleth
Nate Klingenstein
ndk at signet.id
Wed Mar 24 06:14:04 UTC 2021
Let me amend my answer a little:
> Just check the relying party entityID from the authentication context
You'll want to look at the relying party context instead.
https://build.shibboleth.net/nexus/service/local/repositories/site/content/java-identity-provider/4.0.1/apidocs/net/shibboleth/idp/profile/context/RelyingPartyContext.html
And, there may be a way to implement your use case using the Function authentication mechanism and the built-in functions I referenced. I haven't personally explored that at all yet, so I can't give you any guidance; someone else on the list may. My prior response kind-of munged the two, but there are links to the relevant Javadocs for an MFA script.
https://wiki.shibboleth.net/confluence/display/IDP4/FunctionAuthnConfiguration
Sorry for the spam,
Nate.
--------
Signet, Inc.
The Art of Access ®
More information about the users
mailing list