Selecting DuoOIDC 'config' based on user attribute in LDAP
Abernathy, Jeff
jeffabernathy at wustl.edu
Thu Nov 2 04:04:52 UTC 2023
Hello folks
Any help greatly appreciated.
The goal here is to using a attribute derived via LDAP form our AD, push people to two different duo configurations. This is of course done pushing to two different API Host.
We have been using Duo and Shib for a while now. In our old setup with the old 'Duo' plugin (actually pre-dates the plugin, but you get it), we effectively cloned the duo authn-config and had two authn/duo setups, one for one config, one for the other. This was accomplished in the MFA scripted context functions that could successfully pull back attributes via shibboleth.AttributeResolverService.
With DuoOIDC I'm having trouble how to create effectively two instance of DuoOIDC to reference at the level of authn. Instead I tried to do the same thing inside the DuoIntegrationStrategy within duo-oidc-authn-config. But I can't figure out how to read attributes from the attributeresolver service there.
How do we instantiate a call to AttributeResolverService?
Is there a different way you would consider pushing to different Duo integrations/configs based on an attribute?
Thank you,
Jeff Abernathy
Washington University
________________________________
The materials in this message are private and may contain Protected Healthcare Information or other information of a sensitive nature. If you are not the intended recipient, be advised that any unauthorized use, disclosure, copying or the taking of any action in reliance on the contents of this information is strictly prohibited. If you have received this email in error, please immediately notify the sender via telephone or return mail.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20231102/4b3b1a76/attachment.htm>
More information about the users
mailing list