available plugins for MFA integration (was: Re: Enabling MFA on Shibboleth IDP 4.01)

Cantor, Scott cantor.2 at osu.edu
Wed Apr 5 12:16:57 UTC 2023


> For self-hosting (which some are required to do) there don't seem to
> be too many alternatives and in the Free/Libre/Opensource world
> there's no real alternative to privacyIDEA if you need to support more
> than TOTP.

Unfortunately I don't see PriviacyIDEA as being too viable, the UI is just awful. A common model is to require passwords for initial enrollment and MFA subsequently to manage tokens, and it didn't even seem to support that (but it was so complicated to set up, I couldn't say for sure).

If that's all there is, then there's really not much, and unfortunately that's what's driving everybody toward the usual suspects.

When I discussed [1] with the author, it emerged that it didn't yet support FIDO (which is the real goal of all this), but was in progress. He did indicate it had been intended to rely on an abstraction of sorts to avoid being totally tied to PrivacyIDEA, but I also know from evaluating things that their API for FIDO is pretty unique/unusual and would be hard to abstract.

Nevertheless, that's the likely starting point for future exploration.

-- Scott

[1] https://doku.tid.dfn.de/en:shibidp:plugin-fudiscr



More information about the users mailing list