Multiple DuoOIDC -- Integration-Specific Principal Sets
Schwendner, Joanne
joanne_schwendner at brown.edu
Thu Sep 19 15:28:25 UTC 2024
I am trying to implement "Integration-Specific Principal Sets" from this
documentation page:
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631604/DuoAuthnConfiguration
I see others have had fun with this over the years -- now it's my turn...
We have already deployed the "Multiple Duo Integrations", and our use is
almost identical to the example: we have a couple of services that should
get the SpecialDuo, and everything else gets the DefaultDuo. We now need
to implement the Distinct Principal Sets.
Also, we did update our Duo for the Universal Prompt. I am not finding a
description of the Distinct Principal Sets specifically for DuoOIDC. I
*think* I have adapted the setup instructions from Old Duo correctly:
listed all the SupportedPrincipals anywhere I can find that they are
configured, turned off addDefaultPrincipals, etc etc. I have learned that
the order of the DuoIntegrationList is very important. In the log, I can
see the IDP is searching for my SpecialDuo integration, but it's still
getting lost when doing SSO and sorting thru results.
I did also find this page in the Shib Knowledge Base, which mentions a bug
in the DuoOIDC, and a workaround. I've added that workaround:
https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1474297850/Supporting+the+REFEDS+MFA+Profile+V4#Supporting-Multiple-Duo-Policies
Still not there..
Does anyone know of any other documentation specifically for the DuoOIDC
version of this functionality? Or a newer description? Did anyone run
into issues/pitfalls implementing this that might help me? anything
specific to DuoOIDC besides the aforementioned bug?
BTW we are running IDP 4.2.1 (yes, I know...)
Joanne
---
Joanne Schwendner
Identity Services
Office of Information Technology
Brown University
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240919/c681223d/attachment.htm>
More information about the users
mailing list