Multiple 2FA mechanism in Shibboleth

Nate Klingenstein ndk at signet.id
Wed Mar 24 06:14:04 UTC 2021


Let me amend my answer a little:

> Just check the relying party entityID from the authentication context

You'll want to look at the relying party context instead.

https://build.shibboleth.net/nexus/service/local/repositories/site/content/java-identity-provider/4.0.1/apidocs/net/shibboleth/idp/profile/context/RelyingPartyContext.html

And, there may be a way to implement your use case using the Function authentication mechanism and the built-in functions I referenced.  I haven't personally explored that at all yet, so I can't give you any guidance; someone else on the list may.  My prior response kind-of munged the two, but there are links to the relevant Javadocs for an MFA script.

https://wiki.shibboleth.net/confluence/display/IDP4/FunctionAuthnConfiguration

Sorry for the spam,
Nate.

--------
Signet, Inc.
The Art of Access ®


More information about the users mailing list