Working example of using Duo AuthAPI/PreAuth call with Shibboleth IdP 5.1?
Michael Grady
mgrady at unicon.net
Thu May 9 15:07:52 UTC 2024
> On May 9, 2024, at 7:27 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
>> Thanks Scott and Chris for the responses, I did get it working, by defining our own copy
>> of the (NonBrowser) DuoIntegration and PreAuth beans (that the IdP has now in duo
>> -oidc-authn-beans.xml) -- with our own Bean IDs of course -- and then referencing those
>> beans in the map we have in mfa-auth-config.xml. So now working again as it did in IdP
>> 4.x.
>
> FWIW, while the classes themselves were of course in the IdP itself, the beans wouldn't have been accessble from the MFA flow's config file/context. So short of defining them yourself as you did, I don't know how it would have worked before.
>
> That's partly what I meant by "not really supported".
>
> We do not have the AuthAPI beans defined globally for shared use but the Admin API beans are globally shared for that reason (thanks to Steven Premeau pointing it out).
>
> -- Scott
>
We were defining our own beans in v4, but just as part of the Map entry value in our "checkMap" within mfa-authn-config.xml. It may just be that I wasn't updating the httpClient-related property values correctly for the PreAuth bean. The frustrating part is that it was "failing silently" in that the arguments we had before for v4 just raised a "flow initialization" error without any further detail as to what it did not like.
--
Michael A. Grady
IAM Architect, Unicon, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240509/a6ebeecd/attachment.htm>
More information about the users
mailing list