Enable MFA/DUO on per SP ?
Mohamed Lrhazi
lrhazi at cua.edu
Wed Mar 1 21:42:46 UTC 2023
Thanks a lot Scott. I think I got it working, using the document you
referenced:
https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1474297850/Supporting+the+REFEDS+MFA+Profile
On Wed, Mar 1, 2023 at 1:25 PM Cantor, Scott via users <users at shibboleth.net>
wrote:
> Conceptually, the point is...you want the IdP to decide whether to reuse
> the previous result(s) based on whether they already meet the SP's
> requirements, and if not, run the flow and then decide within the flow
> whether to run Duo based on whether the Password result meets the
> requirements or not.
>
> None of this is based on the service, it's based on the requirements for
> authentication policy that may apply to any service.
>
> The shipped examples already illustrate this (with IPAddress and Password
> instead of Password and Duo).
>
> See also, the HowTo article in the KB about supporting REFEDS MFA.
>
> Things are only complex if you also have to take into consideration other
> factors such as the user or a group the user is in. That requires more
> complex scripting but you start from the baseline.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230301/bb937007/attachment.htm>
More information about the users
mailing list