Okta's MFA and Shibboleth
Lohr, Donald A - lohrda
lohrda at jmu.edu
Tue Apr 4 21:05:23 UTC 2023
Thanks, very helpful.
Don
On 4/4/23 4:36 PM, Peter Schober via users wrote:
> CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.
> ________________________________
>
> * Lohr, Donald A - lohrda via users<users at shibboleth.net> [2023-04-04 18:50]:
>> I think what I am after is not being asked for correctly and thus likely not
>> being read correctly, because I still feel like I have unanswered questions.
> No, you just keep ignoring or misreading or not understanding what
> several people have been telling you here.
>
> 1. There is no integration to use Okta's MDA from your Shibboleth IDP
> the way one exists for Duo. (The "API" Scott mentioned Duo having
> for this but Okta not offering.)
> 2. The only way to still achieve Okta MDA with the Shibboleth IDP is by
> activating the built-in SAML SP in the Shib IDP and integrating *that*
> SAML SP with Okta (SAML proxying). Okta then only knows your
> Shibboleth IDP/SP combo, it doesn't need to know anything about
> federation, InCommon or R&S.
> 3. Anything you integrate directy with the Okta IDP you configure in
> the Okta IDP, with buttons/icons and with or without MFA as desired.
> 4. Everything else -- including all of the less enterprisey research and
> teaching tools, licensed e-journals, federation, interfederation,
> InCommon, eduGAIN, etc. -- you keep on your Shib IDP as it is today.
> 5. People access those (item 4) protected resources same way they ever
> have. When they need to log in they'll select your (Shib) IDP for
> login (same as ever) and get redirected there. At that point --
> instead of displaying the usual username/password field -- the Shib
> IDP/SP combo will send the request along to Okta and Okta either
> enforces MFA (because you want to use it for anything that comes in
> "via Shibboleth") or it doesn't (because you don't want MFA for
> anything coming in from your Shib IDP).
>
> So you do have your answer:
> It is possible if you give up the login screen from your Shibboleth
> IDP and have it defer any and all authentication business to Okta. (If
> you don't use any consent functionality in your Shib IDP this would
> mean people never even see anything from your Shib IDP -- only Okta
> will be seen.)
> If you do not want to do this (for whatever reason) then you cannot
> use Okta MFA with your Shibboleth IDP. As simple as that.
>
> HTH,
> -peter
> --
> For Consortium Member technical support, seehttps://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!N6YHze6lT7thMl0!NCvT1tgYI8FPsQxFH9KH2_P3QlblKvrkBxF5vs_pGMSbN8hyeYAdAOAWI86IIdYDUsSzYIWQkmDwRk4T$
> To unsubscribe from this list send an email tousers-unsubscribe at shibboleth.net
--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230404/46226d2e/attachment.htm>
More information about the users
mailing list