Ping MFA with Shibboleth IDP 5

Dan McLaughlin dmclaughlin at tech-consortium.com
Mon Aug 25 17:34:31 UTC 2025


Hey Scott,

Yeah, I fingered that out shortly after I posted this, and I have
something working with SAML Auth Configuration.   I'm considering
building a plugin similar to Duo, but I haven't had time to download
the Duo plugin to see how it's implemented and if it would be a
similar approach. My issue now is getting Ping to accept the Subject
from the AuthnRequest and not reprompt the user for their username.

--

Thanks,

Dan

On Mon, Aug 11, 2025 at 7:33 AM Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> > Shibboleth Configuration to Redirect to PingOne MFA
>
> That's insanity, so whether it worked or not, that ain't the way.
>
> If it's a SAML IdP and you want to proxy to it, then regardless of version, that's [1] (or the V4 equivalent).
>
> https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration
>
> That's not MFA (from the IdP's perspective), that's just punting authentication outright to Ping.
>
> -- Scott
>
>


More information about the users mailing list