authn context comparison per relying party
Bobby Lawrence
robertl at jlab.org
Mon Aug 24 16:24:41 UTC 2026
We have a Salesforce instance which is using our IdP for authentication. Salesforce has recently implemented a requirement that admins login with a phishing-resistant MFA method. Our IdP is asserting "https://refeds.org/profile/mfa". Per REFEDs, that should be enough as its definition is "an additional, higher authentication strength, Phishing-Resistant MFA, that protects against adversary-in-the-middle and related phishing attacks."
For whatever reason, Salesforce asserts this as standard "mfa" and not phishing resistant. This is likely a bug they need to fix but in the meantime, we have admins who cannot log in.
I feel like I need to adjust the "shibboleth.AuthenticationPrincipalWeightMap" bean to make this work but I dont see a way to do this for a specific relying party. I do see that the SAML2.SSO bean exposes a "authnContextTranslationStrategy" option to use a custom function for determining the authn context. Will this do what I need it to do?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260824/74dc55c7/attachment.htm>
More information about the users
mailing list