<div dir="ltr">I&#39;m looking at trying to expose additional authentication factors via shibboleth.<div><br></div><div>Our SSO (cosign) can support pretty much anything.  Currently, our only additional factor is based on RSA tokens (and is invoked in shib via TimeSyncToken).</div>

<div><br></div><div>Are the intended uses for the additional SAML2 authentication contexts defined anywhere?  Some of them are obvious (kerberos, ip, x509).  I&#39;m not sure I understand the difference between &quot;Mobile /n/ Factor&quot; contract and unregistered, or the various flavors of Telephony.</div>

<div><br></div><div>When it comes right down to it, I guess we could customize the login handler we&#39;re using to point specific authn contexts to whatever factors we wanted, but I want to make sure we make appropriate choices.</div>

<div><br></div><div>Liam</div></div>