shib-cas plugin authentication attributes

Baron Fujimoto baron at hawaii.edu
Thu Jul 7 01:07:21 UTC 2022


Thanks for the pointers. Are there any examples in the IdP docs of
scripting to access request variables, or perhaps even asserting
AuthnContextClassRef based on request variables?

On Tue, Jul 5, 2022 at 2:20 PM Cantor, Scott via users <users at shibboleth.net>
wrote:

> On 7/5/22, 5:39 PM, "users on behalf of Baron Fujimoto" <
> users-bounces at shibboleth.net on behalf of baron at hawaii.edu> wrote:
>
> >    We use the shib-cas plugin to front our Shibboleth IdP deployment
> with CAS. Can anyone provide pointers to
> > how we can make use of the CAS authentication attributes to define
> comparable attributes on the Shib side?
>
> Presumably a scripted definition that accesses request variables I imagine.
>
> > so hopefully there's also a way to more generally define an attribute,
> outside of REFEDS, for the IdP to assert
> > whether MFA was actually used in the CAS authentication?
>
> The IdP asserts a SAML AuthnContextClassRef to signal authentication
> types, that's how it's done in SAML.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>


-- 
Baron Fujimoto <baron at hawaii.edu> ::: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum descendus pantorum
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220706/c3f4a8ee/attachment.htm>


More information about the users mailing list