Okta's MFA and Shibboleth

Lohr, Donald A - lohrda lohrda at jmu.edu
Tue Apr 4 21:05:23 UTC 2023


Thanks, very helpful.

Don

On 4/4/23 4:36 PM, Peter Schober via users wrote:
> CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.
> ________________________________
>
> * Lohr, Donald A - lohrda via users<users at shibboleth.net>  [2023-04-04 18:50]:
>> I think what I am after is not being asked for correctly and thus likely not
>> being read correctly, because I still feel like I have unanswered questions.
> No, you just keep ignoring or misreading or not understanding what
> several people have been telling you here.
>
> 1. There is no integration to use Okta's MDA from your Shibboleth IDP
>     the way one exists for Duo. (The "API" Scott mentioned Duo having
>     for this but Okta not offering.)
> 2. The only way to still achieve Okta MDA with the Shibboleth IDP is by
>     activating the built-in SAML SP in the Shib IDP and integrating *that*
>     SAML SP with Okta (SAML proxying). Okta then only knows your
>     Shibboleth IDP/SP combo, it doesn't need to know anything about
>     federation, InCommon or R&S.
> 3. Anything you integrate directy with the Okta IDP you configure in
>     the Okta IDP, with buttons/icons and with or without MFA as desired.
> 4. Everything else -- including all of the less enterprisey research and
>     teaching tools, licensed e-journals, federation, interfederation,
>     InCommon, eduGAIN, etc. -- you keep on your Shib IDP as it is today.
> 5. People access those (item 4) protected resources same way they ever
>     have. When they need to log in they'll select your (Shib) IDP for
>     login (same as ever) and get redirected there. At that point --
>     instead of displaying the usual username/password field -- the Shib
>     IDP/SP combo will send the request along to Okta and Okta either
>     enforces MFA (because you want to use it for anything that comes in
>     "via Shibboleth") or it doesn't (because you don't want MFA for
>     anything coming in from your Shib IDP).
>
> So you do have your answer:
> It is possible if you give up the login screen from your Shibboleth
> IDP and have it defer any and all authentication business to Okta. (If
> you don't use any consent functionality in your Shib IDP this would
> mean people never even see anything from your Shib IDP -- only Okta
> will be seen.)
> If you do not want to do this (for whatever reason) then you cannot
> use Okta MFA with your Shibboleth IDP. As simple as that.
>
> HTH,
> -peter
> --
> For Consortium Member technical support, seehttps://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!N6YHze6lT7thMl0!NCvT1tgYI8FPsQxFH9KH2_P3QlblKvrkBxF5vs_pGMSbN8hyeYAdAOAWI86IIdYDUsSzYIWQkmDwRk4T$
> To unsubscribe from this list send an email tousers-unsubscribe at shibboleth.net

-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230404/46226d2e/attachment.htm>


More information about the users mailing list