<div dir="ltr"><div style="font-family:arial,sans-serif;font-size:13px">Scott,<br></div><div style="font-family:arial,sans-serif;font-size:13px"><br></div><div style="font-family:arial,sans-serif;font-size:13px">I&#39;d like to follow up on your reply to my inquiry in February on the shibboleth user list. In February we were researching two factor shibboleth options. </div>


<div style="font-family:arial,sans-serif;font-size:13px"><br></div><div style="font-family:arial,sans-serif;font-size:13px">Now we&#39;ve got a working trial of RSA two-factor with our VPN. We&#39;ve got the RSA Authentication Manager v8 and the Web Tier running as a test with our Cisco VPN. We&#39;re trying to integrate RSA with shibboleth, but we&#39;re not sure how to get our idp server to use RSA server to authenticate. RSA has directed us to the Multi Factor Login Handler link below, but our technical contacts have not been able to give any instruction or documentation beyond this link.</div>


<div style="font-family:arial,sans-serif;font-size:13px"><br></div><div><font face="arial, sans-serif"><a href="https://www.google.com/url?q=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fdisplay%2FSHIB2%2FMulti%2BFactor%2BLogin%2BHandler&amp;sa=D&amp;sntz=1&amp;usg=AFQjCNFpLnJgfHEhP2LBwjpi3VZYCDzgLQ" target="_blank">https://www.google.com/url?q=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fdisplay%2FSHIB2%2FMulti%2BFactor%2BLogin%2BHandler&amp;sa=D&amp;sntz=1&amp;usg=AFQjCNFpLnJgfHEhP2LBwjpi3VZYCDzgLQ</a></font><br>


</div><div style="font-family:arial,sans-serif;font-size:13px"><br></div><div style="font-family:arial,sans-serif;font-size:13px">I understand that the Multi Factor Login Handler can check against multiple factors, but don&#39;t have any instruction on how to tell shibboleth to see RSA as an authenticator. </div>


<div style="font-family:arial,sans-serif;font-size:13px"><br></div><div style="font-family:arial,sans-serif;font-size:13px">We have created a special shibboleth server just for this test. After we test RSA we&#39;re going to look at duo so we have two vendors to compare. We&#39;ve looked for documentation but all we could find about two factor and shibboleth was about duo security.<br>


</div><div class="gmail_extra" style="font-family:arial,sans-serif;font-size:13px"><br></div><div class="gmail_extra" style="font-family:arial,sans-serif;font-size:13px"><br></div><div class="gmail_extra" style="font-family:arial,sans-serif;font-size:13px">


Thanks<div><div><br></div><div><img src="https://mail.google.com/mail/u/1/images/cleardot.gif"></div></div><div>Jared</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">
On Fri, Feb 15, 2013 at 9:06 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">


<div>On 2/15/13 3:04 PM, &quot;Jared Hoffman&quot; &lt;<a href="mailto:hoffmanj@kenyon.edu" target="_blank">hoffmanj@kenyon.edu</a>&gt; wrote:<br>
<br>
&gt;Has anyone had any experience integrating Shibboleth with two factor<br>
&gt;authentication? The two vendors we are looking at, which claim they<br>
&gt;can work with shibboleth, are RSA and Safe-Net. If you have any<br>
&gt;experience with these and shibboleth, please let me know if you have<br>
&gt;been able to make it work.<br>
<br>
</div>I do SecurID via a JAAS login module I got from RSA. That part&#39;s basically<br>
nothing, it&#39;s the same as standard user/pass with Kerberos or LDAP. I<br>
wrapped it in more custom behavior to meet local needs, but that&#39;s not so<br>
much anything to do with two-factor.<br>
<br>
If you qualify your use case with more details about the impact of your<br>
two-factor approach relative to other methods you offer, and how it will<br>
be expected to interact with SPs, I can possibly provide more details.<br>
<span><font color="#888888"><br>
-- Scott<br>
</font></span><div><div><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br>Jared Hoffman<br>System Manager<br>Kenyon College<br><a href="mailto:hoffmanj@kenyon.edu" target="_blank">hoffmanj@kenyon.edu</a><br><a href="tel:740.427.5948" value="+17404275948" target="_blank">740.427.5948</a><br>

<br>
</div></div>