MFA AuthnContext Transformation with SAML Proxy
Steven Premeau
steven.premeau at maine.edu
Wed Nov 20 19:23:14 UTC 2024
Once again, this appears to be a question for Okta, as they should not be
(only) returning PasswordProtectedTransport if MFA is in use.
You would not want to globally replace that Authentication Context Class
with one asserting MFA unless you are positive that the MFA requirement(s)
to assert the REFEDS context have been met *everytime*
PasswordProtectedTransport
is in the SAML response.
There is support included for mapping unique values during the proxy
process, intended for use when their responses differ from the values you
seek, but still distinct values returned from the proxied IDP.
Assuming you (or your client) is not attempt to misrepresent the
strength of any authentication, you may want to look at the following
resources -- these are Azure AD examples, but should be of some help:
https://shibboleth.atlassian.net/wiki/spaces/KB/pages/2783936889/SAML+Proxying+EntraID+Azure+with+the+Shibboleth+IdP#SAMLProxyingEntraID/AzurewiththeShibbolethIdP-ProxyTask6.HandlingREFEDSAuthnContextRequests(optional)
https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505085/AuthenticationConfiguration#Advanced-Topics
(Under Proxying)
Steve.
On Wed, Nov 20, 2024 at 11:28 AM S, Kalidasan via users <
users at shibboleth.net> wrote:
> Hi Team,
>
> As part of our recent client engagement, we enabled SAML proxy for
> Shibboleth IDP and configured Okta as upstream IDP.
>
>
>
> In the SAML assertion issued by Shibboleth IDP to the downstream SP
> applications, we can observe that Okta’s authentication context class “
> *urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport*” is
> sent as classRef value. We need to replace this value with “
> https://refeds.org/profile/mfa” value in SAML response generated by
> Shibboleth IDP as before otherwise some of the underlying SPs may fail SSO,
> considering this as invalid MFA authentication context class reference
> *(<saml2:AuthnContextClassRef>).*
>
>
>
> While exploring the Shibboleth documentations we can find below article
> talking about *authnContextTranslationStrategy* and
> *authnContextTranslationStrategyEx*, but there are no proper examples on
> how to use these with SSO profile and what bean and properties can be used
> together.
>
>
>
> ProfileConfiguration-SAML2SSO - Identity Provider 4 - Confluence
> <https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631686/ProfileConfiguration-SAML2SSO>
>
>
>
> *Our version: V4.3.3*
>
>
>
> Kindly can you share with us any other Shibboleth documentation or example
> syntax to achieve the above translation?
>
>
>
> Thanks and Regards
> Kalidasan S
> Advisory - Senior Solution Advisor
> Cyber IAM(Okta) | Deloitte US India Risk and Financial Advisory
>
> kalids at deloitte.com | www.deloitte.com
>
>
>
> This message (including any attachments) contains confidential information
> intended for a specific individual and purpose, and is protected by law. If
> you are not the intended recipient, you should delete this message and any
> disclosure, copying, or distribution of this message, or the taking of any
> action based on it, by you is strictly prohibited.
>
> Deloitte refers to a Deloitte member firm, one of its related entities, or
> Deloitte Touche Tohmatsu Limited ("DTTL"). Each Deloitte member firm is a
> separate legal entity and a member of DTTL. DTTL does not provide services
> to clients. Please see www.deloitte.com/about to learn more.
>
> v.E.1
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20241120/b94f9351/attachment.htm>
More information about the users
mailing list