Okta's MFA and Shibboleth
Lohr, Donald A - lohrda
lohrda at jmu.edu
Tue Apr 4 14:42:30 UTC 2023
It seems that if apps are in the Okta portal are still configured
against Shibboleth IdP, that yes SAML proxying between Okta and Shib IdP
is the method. But that assumes that all apps have an icon in the Okta
portal.
Professors point their students research/periodicals sites and SSO login
works because of InCommon Federation membership. There is no way all of
these will get an icon in the Okta portal. If MFA is still a goal for
these Shibboleth protected applications, does anyone know if Shibboleth
IdP can be configured to use Okta's MFA solution?
Thanks,
Don
On 4/4/23 10:19 AM, Cantor, Scott wrote:
> CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.
> ________________________________
>
> Most likely it relies on fully devolving all authentication to Okta via SAML proxying, in which case I'm sure it works, modulo Okta's lousy SAML compliance. Duo is an outlier in supplying just the second factor with a custom API.
>
> -- Scott
>
>
--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230404/7b3ec2f9/attachment.htm>
More information about the users
mailing list