Research.gov MFA

Cantor, Scott cantor.2 at osu.edu
Fri Mar 7 15:49:44 UTC 2025


> Research.gov is not setup to explicitly ask for REFEDS MFA at
> this time. If you don't require REFEDS MFA for everybody,
> then you need to configure a relying party override to
> indicate that REFEDS MFA is the only allowed context when
> an AuthnRequest comes from them. Not ideal, but that's
> where things stand today.

Or you tell  them to pound sand. I'm not getting into the business of manually configuring my IdP to perform MFA for external services, I find that incomprehensible.

I haven't done it, and don't plan to. They want it, they can ask for it, and if they're not checking the result (which I suspect is the case) then that goes triple.

-- Scott




More information about the users mailing list