available plugins for MFA integration
Peter Schober
peter.schober at univie.ac.at
Fri Apr 7 15:58:10 UTC 2023
* Scott Cantor <cantor.2 at osu.edu> [2023-04-07 17:25]:
> In effect it was my feeling that us saying "to use Shibboleth to do
> FIDO, you need to install and learn PrivacyIdea" was not going to be
> a story that would sway a lot of people.
Right. Just for context: The whole point of PI is to centralize token
management (and then ideally combine it with SSO IDPs to re-use those
tokens with as many resources as possible).
In other words, even if Shib did FIDO2 all by itself people will still
need something like PI to get strong auth for all their *other*
systems: VPNs, WiFi, non-web, etc. (though arguably then it's no
longer your concern.) -- unless they're prepared to tell their
constituency to self-register/spread their tokens across dozens of
applications (self-register to app A, then app B, etc. and then suffer
through revoking and replacing lost tokens with each app individually).
But that's a very different focus and probably impossible to align
with what's in scope for the Shib IDP.
(Just like IDM is a basic need/concern for every org but Shib itself
can't help you there. You'd need to go set up and learn midPoint etc.)
-peter
More information about the users
mailing list