Ping MFA with Shibboleth IDP 5

Cantor, Scott cantor.2 at osu.edu
Mon Aug 25 17:40:29 UTC 2025


The Duo plugin is an implementation of an OpenID Connect client with some modifications to fit Duo's non-standard behavior and do some value-add on top of that.

It's not a fit for anything else really, though we talked about potentially trying to collapse it into the main RP plugin someday. I doubt it happens before Duo itself Cisco's themselves into oblivion.

>  My issue now is getting Ping to accept the Subject
> from the AuthnRequest and not reprompt the user for
> their username.

That isn't exactly what the field in the request is for. There is no "login hint" concept in SAML.

That field is about tailoring assertions if one is imnplementing an STS using SAML protocol, it was a finger in the eye of the WS-* people to prove we could do the kinds of things they did.

-- Scott




More information about the users mailing list