Research.gov MFA
Zico
mailzico at gmail.com
Fri Mar 7 15:17:39 UTC 2025
Hi,
I am trying to configure my Shibboleth v4 IDP for Research.gov MFA. And I
believe I configured everything from my side as NIH federation MFA is
working fine. [ Fine means, I do see NIH enforcing "
https://refeds.org/profile/mfa" in "AuthnContextClassRef" in SAML assertion
].
But for Researdh.gov I don't see anything like this. Do you have any
suggestions what's wrong with my setup? I tried to contact Research.gov
support but not getting enough responses.
Here is what I am getting when I am testing my SSO with Research.gov:
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
ID="0000xxxxdcc39b4e5c90862"
Version="2.0"
IssueInstant="2025-03-07T15:09:40Z"
Destination="
https://myhostname/idp/profile/SAML2/POST/SSO"
ForceAuthn="false"
IsPassive="false"
ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
AssertionConsumerServiceURL="
https://identity.acpt.research.gov/sso/Consumer/metaAlias/research/identity.acpt.research.gov
"
>
<saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
https://identity.acpt.research.gov/sso/sp</saml:Issuer>
<samlp:NameIDPolicy xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
SPNameQualifier="
https://identity.acpt.research.gov/sso/sp"
AllowCreate="true"
/>
<samlp:RequestedAuthnContext
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
Comparison="exact"
/>
</samlp:AuthnRequest>
Thanks in advance!
--
Best,
Zico
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250307/a0256dfe/attachment.htm>
More information about the users
mailing list