shib-cas plugin authentication attributes
Baron Fujimoto
baron at hawaii.edu
Tue Jul 5 21:39:05 UTC 2022
We use the shib-cas plugin to front our Shibboleth IdP deployment with CAS.
Can anyone provide pointers to how we can make use of the CAS
authentication attributes to define comparable attributes on the Shib side?
If you test CAS logins using /cas/login, we can see, for example, we the
following set of authentication attributes:
credentialType, clientIpAddress, samlAuthenticationStatementAuthMethod,
authenticationDate, bypassMultifactorAuthentication, authenticationMethod,
authnContextClass, successfulAuthenticationHandlers, serverIpAddress,
userAgent
In particular, we're interested in whether MFA was used for the
authentication.
We've noted that the shib-cas plugin supports the REFEDS MFA profile, which
suggests perhaps it's using the conditional expression
(authn_method=mfa-duo && authnContextClass=mfa-duo) as the basis for its
MFA assertions(?), so hopefully there's also a way to more generally define
an attribute, outside of REFEDS, for the IdP to assert whether MFA was
actually used in the CAS authentication?
--
Baron Fujimoto <baron at hawaii.edu> ::: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum descendus pantorum
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220705/76f9524f/attachment.htm>
More information about the users
mailing list