SPNEGO as first factor in MFA
Simon Lundström
simlu at su.se
Mon Mar 31 09:18:17 UTC 2025
On Mon, 2025-03-31 at 09:58:38 +0200, Rabe, Jens wrote:
> Hi Simon,
>
> >On Fri, 2025-03-28 at 19:08:42 +0100, Rabe, Jens via users wrote:
> >>[...]
> >> And it works but if i authenticate at the service provide that requested the forceAuthn and after
> >> successful login i try to login at a service provide with SPNEGO and that fails with "Profile Action
> >> SelectSubjectCanonicalizationFlow: No potential flows left to choose from, canonicalization will fail".
>
> >Did you set:
> >idp.authn.SPNEGO.forcedAuthenticationSupported = true
> >like I wrote in https://marc.info/?l=shibboleth-users&m=174238364408577&w=2
> >?
>
> I saw your post and noticed that we have very similar problems.
> But I thought I shouldn't enable support for ForceAuthn in SPNEGO, since SPNEGO doesn't support ForceAuthn anyway.
> But I'll try enabling it.
I had the same objections in my mind. But..
> I'd still prefer that MFA handle the transition filtering. But I still don't have an idea for that.
...the flow "disables" SPNEGO via the MFA flow since if forceAuth is set
it *always* redirects to auth/Password.
BR,
- Simon
More information about the users
mailing list