SPNEGO as first factor in MFA

Simon Lundström simlu at su.se
Mon Mar 31 09:18:17 UTC 2025


On Mon, 2025-03-31 at 09:58:38 +0200, Rabe, Jens wrote:
> Hi Simon,
> 
> >On Fri, 2025-03-28 at 19:08:42 +0100, Rabe, Jens via users wrote:
> >>[...]
> >> And it works but if i authenticate at the service provide that requested the forceAuthn and after 
> >> successful login i try to login at a service provide with SPNEGO and that fails with "Profile Action 
> >> SelectSubjectCanonicalizationFlow: No potential flows left  to choose from, canonicalization will fail".
> 
> >Did you set:
> >idp.authn.SPNEGO.forcedAuthenticationSupported = true
> >like I wrote in  https://marc.info/?l=shibboleth-users&m=174238364408577&w=2
> >?
> 
> I saw your post and noticed that we have very similar problems.
> But I thought I shouldn't enable support for ForceAuthn in SPNEGO, since SPNEGO doesn't support ForceAuthn anyway.
> But I'll try enabling it.

I had the same objections in my mind. But..

> I'd still prefer that MFA handle the transition filtering. But I still don't have an idea for that.

...the flow "disables" SPNEGO via the MFA flow since if forceAuth is set
it *always* redirects to auth/Password.

BR,
- Simon


More information about the users mailing list