<div dir="ltr">never mind.  found it in <a href="http://docs.oasis-open.org/security/saml/v2.0/saml-authn-context-2.0-os.pdf">http://docs.oasis-open.org/security/saml/v2.0/saml-authn-context-2.0-os.pdf</a><div><br></div><div>

Liam</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Wed, Sep 25, 2013 at 4:48 PM, Liam Hoekenga <span dir="ltr">&lt;<a href="mailto:liamr@umich.edu" target="_blank">liamr@umich.edu</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">I&#39;m looking at trying to expose additional authentication factors via shibboleth.<div><br></div><div>

Our SSO (cosign) can support pretty much anything.  Currently, our only additional factor is based on RSA tokens (and is invoked in shib via TimeSyncToken).</div>
<div><br></div><div>Are the intended uses for the additional SAML2 authentication contexts defined anywhere?  Some of them are obvious (kerberos, ip, x509).  I&#39;m not sure I understand the difference between &quot;Mobile /n/ Factor&quot; contract and unregistered, or the various flavors of Telephony.</div>


<div><br></div><div>When it comes right down to it, I guess we could customize the login handler we&#39;re using to point specific authn contexts to whatever factors we wanted, but I want to make sure we make appropriate choices.</div>

<span class="HOEnZb"><font color="#888888">
<div><br></div><div>Liam</div></font></span></div>
</blockquote></div><br></div>