Enabling MFA on Shibboleth IDP 4.01

Francis Jayakanth francis at iisc.ac.in
Tue Feb 22 06:45:56 UTC 2022


Thank you, Scott, for the explanation. I will check if our IdP is  "REFEDS MFA profile compliant".

 -Francis
________________________________
From: Cantor, Scott <cantor.2 at osu.edu>
Sent: 21 February 2022 22:07
To: Shib Users <users at shibboleth.net>
Cc: Francis Jayakanth <francis at iisc.ac.in>
Subject: Re: Enabling MFA on Shibboleth IDP 4.01

External Email


On 2/21/22, 11:17 AM, "users on behalf of Francis Jayakanth via users" <users-bounces at shibboleth.net on behalf of users at shibboleth.net> wrote:

> Does it mean that our IdP should be MFA compliant and that, if it is not, there is no way to gain access to the
> site via the institutional login process?

There is no such thing as "MFA compliant". There's "REFEDS MFA profile compliant", which involves a determination as to the suitability of a deployment to meet the profile's (incredibly minimal) requirements and then supporting the signaling of the defined AuthnContextClassRef value within one's IdP. NIH is requesting that context, so the IdP either understands it, or it fails. Failure is not an error, it's a compliant response to being asked for something it doesn't know how to do.

You have to understand the IdP's features in the area of context class signaling. and add the necessary configuration for that to work. Doing so is much more complex in the face of using something like Azure, which is deficient in supporting the SAML standard, or it would be relatively simple.

There are HowTos in the wiki about supporting the REFEDS context in general for a local MFA deployment, but I don't know that there are any regarding how to do it with Azure, I imagine some of it is site specific. There are people that use it that could probably provide that sort of information, but I'm not among them.

-- Scott


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220222/68afd204/attachment.htm>


More information about the users mailing list