Okta's MFA and Shibboleth
Herron, Joel D
herronj at uww.edu
Tue Apr 4 15:28:14 UTC 2023
Don,
We are in the process of setting up okta. I can tell you that I have successfully proxied the IDP back to Okta and then you can use whatever MFA method you want to inside of Okta. We are still using Duo through Okta and it is working just fine. I will also heavily agree with Scott Okta’s SAML implementation is trash.
All I had to do was follow the proxy to another IDP guide and it was an easy setup.
Joel Herron
DevOps Engineer
ICIT
UW-Whitewater
From: users <users-bounces at shibboleth.net> on behalf of Lohr, Donald A - lohrda via users <users at shibboleth.net>
Date: Tuesday, April 4, 2023 at 10:21 AM
To: Cantor, Scott <cantor.2 at osu.edu>, Shib Users <users at shibboleth.net>
Cc: Lohr, Donald A - lohrda <lohrda at jmu.edu>
Subject: Re: Okta's MFA and Shibboleth
EXTERNAL EMAIL
Basically my question is: Can a Shibboleth IdP be configured to use the Okta vendor's MFA product?
Thanks,
Don
On 4/4/23 11:00 AM, Cantor, Scott wrote:
CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.
________________________________
What may be true however is that you may not have the ability to control which applications get MFA'd by Okta, given that they very likely do not support the actual proxying semantics of SAML or have the ability to consume the RequesterID element to influence behavior.
So if you didn't mean all or nothing re: MFA, then you may be correct.
-- Scott
--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230404/98b8392c/attachment.htm>
More information about the users
mailing list