General Question on 2FA support and Third Party Authentication Services

Wessel, Keith kwessel at illinois.edu
Wed Mar 31 16:11:56 UTC 2021


Yes, it could. But unless the underlying service either always does 2FA or has a way of communicating back to the IdP whether or not 2FA was done, you wouldn't be able to accurately return the authn context class ref value to the SP. You'd need to know if 2FA was part of the external authentication or not and return either password or an MFA context to the requesting SP based on that.

Keith


From: users <users-bounces at shibboleth.net> On Behalf Of Ullfig, Roberto Alfredo
Sent: Wednesday, March 31, 2021 10:39 AM
To: Shib Users <users at shibboleth.net>
Subject: General Question on 2FA support and Third Party Authentication Services

For a SAML implementation does Shibboleth need to know about 2FA. I know it supports it (and I've tested that) but could the underlying authentication service itself (as in the case of a third party application) do the 2FA on its own and Shibboleth be totally unaware that 2FA is part of the authentication process?

---
Roberto Ullfig - rullfig at uic.edu<mailto:rullfig at uic.edu>
Systems Administrator
Enterprise Applications & Services | Technology Solutions
University of Illinois - Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210331/03754319/attachment.htm>


More information about the users mailing list