<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Fri, Apr 4, 2014 at 4:20 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="">On 4/4/14, 5:06 PM, "David Langenberg" <<a href="mailto:davel@uchicago.edu">davel@uchicago.edu</a>> wrote:<br>
><br>
>The SP needs to send the "assurance" requirement via the<br>
>AuthnContextClassRef field of the AuthRequest. You can't control on the<br>
>IdP side "SP X requests must do DUO".<br>
<br>
</div>Was that established? I thought you could specify a<br>
defaultAuthenticationMethod for a relying party per usual and the MCB<br>
could at least see it.<br></blockquote><div><br></div><div>I understood a recent post from Paul said no, it couldn't be done. Paul?</div><div><br></div><div>Dave</div></div><div><br></div>-- <br>David Langenberg<div>
Identity & Access Management</div><div>The University of Chicago</div>
</div></div>