<div dir="ltr">I'm looking at trying to expose additional authentication factors via shibboleth.<div><br></div><div>Our SSO (cosign) can support pretty much anything. Currently, our only additional factor is based on RSA tokens (and is invoked in shib via TimeSyncToken).</div>
<div><br></div><div>Are the intended uses for the additional SAML2 authentication contexts defined anywhere? Some of them are obvious (kerberos, ip, x509). I'm not sure I understand the difference between "Mobile /n/ Factor" contract and unregistered, or the various flavors of Telephony.</div>
<div><br></div><div>When it comes right down to it, I guess we could customize the login handler we're using to point specific authn contexts to whatever factors we wanted, but I want to make sure we make appropriate choices.</div>
<div><br></div><div>Liam</div></div>