authn context comparison per relying party

Bobby Lawrence robertl at jlab.org
Mon Aug 24 16:24:41 UTC 2026


We have a Salesforce instance which is using our IdP for authentication.  Salesforce has recently implemented a requirement that admins login with a phishing-resistant MFA method.  Our IdP is asserting "https://refeds.org/profile/mfa".  Per REFEDs, that should be enough as its definition is "an additional, higher authentication strength, Phishing-Resistant MFA, that protects against adversary-in-the-middle and related phishing attacks."
For whatever reason, Salesforce asserts this as standard "mfa" and not phishing resistant.  This is likely a bug they need to fix but in the meantime, we have admins who cannot log in.
I feel like I need to adjust the "shibboleth.AuthenticationPrincipalWeightMap" bean to make this work but I dont see a way to do this for a specific relying party.  I do see that the SAML2.SSO bean exposes a "authnContextTranslationStrategy" option to use a custom function for determining the authn context.  Will this do what I need it to do?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260824/74dc55c7/attachment.htm>


More information about the users mailing list