Research.gov MFA

Zico mailzico at gmail.com
Fri Mar 7 18:16:17 UTC 2025


Hi Michael,

Thanks for the quick reply!  So, if I understand correctly, a relying party
override is my only option to force MFA for Research.gov, even though they
don't explicitly request it?  Could you point me to any documentation or
examples on how to implement this override in Shibboleth IDP?

Best,
Zico




On Fri, Mar 7, 2025 at 9:25 PM Michael Grady <mgrady at unicon.net> wrote:

>
>
> On Mar 7, 2025, at 9:17 AM, Zico via users <users at shibboleth.net> wrote:
>
>
> I am trying to configure my Shibboleth v4 IDP for Research.gov
> <http://research.gov/> MFA. And I believe I configured everything from my
> side as NIH federation MFA is working fine. [ Fine means, I do see NIH
> enforcing "https://refeds.org/profile/mfa" in "AuthnContextClassRef" in
> SAML assertion ].
>
> But for Researdh.gov <http://researdh.gov/> I don't see anything like
> this. Do you have any suggestions what's wrong with my setup? I tried to
> contact Research.gov <http://research.gov/> support but not getting
> enough responses.
>
>
> Research.gov is not setup to explicitly ask for REFEDS MFA at this time.
> If you don't require REFEDS MFA for everybody, then you need to configure a
> relying party override to indicate that REFEDS MFA is the only allowed
> context when an AuthnRequest comes from them. Not ideal, but that's where
> things stand today.
>
> --
> Michael A. Grady
> IAM Architect, Unicon, Inc.
>
>
>
>

-- 
Best,
Zico
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250308/9967582a/attachment.htm>


More information about the users mailing list