Shibboleth IDP v4.2 : Disable AuthContextClassRef Check in SAML Proxying
Peter Schober
peter.schober at univie.ac.at
Thu Jul 28 08:01:36 UTC 2022
* Prasanna CG via users <users at shibboleth.net> [2022-07-28 05:57]:
> In this process, the SP first requests authcontext of “Password
> Protected“ in the auth request.
Not a direct answer to your actual question but of this is literally
what the SP requests, well, it shouldn't be requesting anything at all:
Password-based authentication is arguably the weakest possible
authentication method and by not requesting anything instead authn
methods at any of the involved IDPs couldn't possibly get any worse
(weaker), but may potentially get better (stronger)!
So if the SP can be changed to stop doing requesting a specific authn
method then I guess this would still solve your problem.
-peter
More information about the users
mailing list