<div dir="ltr">Hi Rich,<div><br></div><div>The SP needs to send the &quot;assurance&quot; requirement via the AuthnContextClassRef field of the AuthRequest.  You can&#39;t control on the IdP side &quot;SP X requests must do DUO&quot;.</div>
<div><br></div><div>See: <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessionInitiator#NativeSPSessionInitiator-SAML2SessionInitiator(ProtocolHandler)">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessionInitiator#NativeSPSessionInitiator-SAML2SessionInitiator(ProtocolHandler)</a></div>
<div><br></div><div>As for your second question, once again, it&#39;s on the Service to say &quot;hmm, this user is from Nigeria, I should make them to 2-factor&quot; and then send the appropriate request to the Identity Provider.  The MCB only affects policy from the point of view of &quot;can this individual meet this requested Authentication Context by either using a comparable context (bronze is requested, user has silver &amp; MCB knows that silver &gt; bronze) or user can satisfy that authentication context&quot;.</div>
<div><br></div><div>Dave<br><br></div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Fri, Apr 4, 2014 at 2:42 PM, Rich Graves <span dir="ltr">&lt;<a href="mailto:rgraves@carleton.edu" target="_blank">rgraves@carleton.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div><div style="font-size:12pt;font-family:arial,helvetica,sans-serif">I have a test Shib 2.4 instance with multi-context-broker and its Duo plugin working. By setting a per-user LDAP attribute mapped to &quot;assurance,&quot; I can toggle the 2FA requirement off and on. Thanks!<br>
<br>I have not yet figured out how to configure a specific SP to require higher assurance, though I see that it&#39;s very much intended to work. I&#39;m sure I&#39;ll figure it out eventually, but more explicit pointers would be welcome.<br>
<br>Next step, has anyone looked into changing the MCB assurance requirement if the source IP address or geocode is suspicious? For example, webmail logins from Nigeria, or some &quot;grand unified logging program&quot; that knows that this username logged on from three different continents today. Is HTTP REMOTE_ADDR address available to resolver:DataConnectors? I know that some big .edu&#39;s have done this sort of thing before, but I&#39;m pretty sure that work predates MCB.<span class="HOEnZb"><font color="#888888"><br>
-- <br><div><span name="x"></span>Rich Graves &lt;<a href="mailto:rgraves@carleton.edu" target="_blank">rgraves@carleton.edu</a>&gt;<br></div></font></span></div></div><br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br>David Langenberg<div>Identity &amp; Access Management</div>
<div>The University of Chicago</div>
</div>