shib-cas plugin authentication attributes

Cantor, Scott cantor.2 at osu.edu
Wed Jul 6 00:19:57 UTC 2022


On 7/5/22, 5:39 PM, "users on behalf of Baron Fujimoto" <users-bounces at shibboleth.net on behalf of baron at hawaii.edu> wrote:

>    We use the shib-cas plugin to front our Shibboleth IdP deployment with CAS. Can anyone provide pointers to
> how we can make use of the CAS authentication attributes to define comparable attributes on the Shib side?

Presumably a scripted definition that accesses request variables I imagine.

> so hopefully there's also a way to more generally define an attribute, outside of REFEDS, for the IdP to assert
> whether MFA was actually used in the CAS authentication?

The IdP asserts a SAML AuthnContextClassRef to signal authentication types, that's how it's done in SAML.

-- Scott




More information about the users mailing list