Enabling MFA on Shibboleth IDP 4.01
Cantor, Scott
cantor.2 at osu.edu
Mon Feb 21 16:37:14 UTC 2022
On 2/21/22, 11:17 AM, "users on behalf of Francis Jayakanth via users" <users-bounces at shibboleth.net on behalf of users at shibboleth.net> wrote:
> Does it mean that our IdP should be MFA compliant and that, if it is not, there is no way to gain access to the
> site via the institutional login process?
There is no such thing as "MFA compliant". There's "REFEDS MFA profile compliant", which involves a determination as to the suitability of a deployment to meet the profile's (incredibly minimal) requirements and then supporting the signaling of the defined AuthnContextClassRef value within one's IdP. NIH is requesting that context, so the IdP either understands it, or it fails. Failure is not an error, it's a compliant response to being asked for something it doesn't know how to do.
You have to understand the IdP's features in the area of context class signaling. and add the necessary configuration for that to work. Doing so is much more complex in the face of using something like Azure, which is deficient in supporting the SAML standard, or it would be relatively simple.
There are HowTos in the wiki about supporting the REFEDS context in general for a local MFA deployment, but I don't know that there are any regarding how to do it with Azure, I imagine some of it is site specific. There are people that use it that could probably provide that sort of information, but I'm not among them.
-- Scott
More information about the users
mailing list