Duo OIDC plugin Issue

Jason Rotunno jrotunno at swarthmore.edu
Wed Mar 16 16:12:14 UTC 2022


So I changed the idp.authn.DuoOIDC.supportedPrincipals value to saml2/
https://refeds.org/profile/mfa since that's another value I saw in
general-authn.xml and the docs said to consider it. Fortunately, that
works. I don't understand Shib and SAML well enough to know why it works,
but it works. If anyone wants to point me to where I can read up to get a
better handle on it, it would be appreciated.

Jason


On Wed, Mar 16, 2022 at 11:47 AM Jason Rotunno <jrotunno at swarthmore.edu>
wrote:

> We're running Shibboleth IDP 4.1.5 and I'm attempting to move from the
> previous native Duo implementation (which involved the files
> conf/idp.properties, conf/authn/duo.properties,
> conf/authn/general-authn.xml, and conf/authn/mfa-authn-config.xml) to the
> Duo OIDC plugin.
>
> I followed the documentation at
> https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1374027959/DuoOIDCAuthnConfiguration
> and the only section I don't understand is 'Authentication Context Classes
> (i.e., Supported Principals)'. It's not clear to me what needs to be
> changed, where, and to what. I decided to skip it and so far several SPs
> that I've tested work. However, I'm running into a problem logging into the
> InCommon Certificate Manager webapp. The error returned by the webapp is:
>
> Status: urn:oasis:names:tc:SAML:2.0:status:Requester
> Sub-Status: urn:oasis:names:tc:SAML:2.0:status:NoAuthnContext
> Message: An error occurred.
>
>
> And the Shib logs have:
>
> 2022-03-16 11:22:26,208 - WARN
> [net.shibboleth.idp.authn.impl.FinalizeAuthentication:166] - [x.y.z.a] -
> Profile Action FinalizeAuthentication: Authentication result for flow
> authn/MFA did not satisfy the request
> 2022-03-16 11:22:26,259 - WARN
> [org.opensaml.profile.action.impl.LogEvent:101] - [x.y.z.a] - A non-proceed
> event occurred while processing the request: RequestUnsupported
>
>
> I don't know if this is related to the 'Supported Principals' step so in
> duo-oidc.properties I tried changing the
> idp.authn.DuoOIDC.supportedPrincipals value from saml2/
> http://example.org/ac/classes/mfa. The values I tried are:
>
> saml2/http://<domain>/ac/classes/mfa
> saml2/http://<fqdn of idp>/ac/classes/mfa
> saml2/http://id.incommon.org/assurance/mfa (I saw this referenced in
> general-authn.xml so I figured I'd give it a try)
>
>
> None of them worked, but again I'm not even sure this is related to the
> issue.
>
> Any suggestions?
>
> Thanks,
> Jason
>
> --
>
> Jason Rotunno
> System & Security Administrator
> Swarthmore College
> 500 College Ave
> Swarthmore, PA 19081
> 610.328.8505
>
> *VERIFY before you click!!*
>   - Attackers make their emails look like they come from someone they don't.
>   - Attackers make links look like they go to websites they don't.
>   - Attackers disguise malware as receipts, invoices, faxes, etc.
>
> Forward suspicious emails to phishing at swarthmore.edu.
>
>

-- 

Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505

*VERIFY before you click!!*
  - Attackers make their emails look like they come from someone they don't.
  - Attackers make links look like they go to websites they don't.
  - Attackers disguise malware as receipts, invoices, faxes, etc.

Forward suspicious emails to phishing at swarthmore.edu.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220316/a6a20eb7/attachment.htm>


More information about the users mailing list