<div dir="ltr">1 sounds viable.  Duo, I believe, can strip the @<a href="http://ad.example.edu">ad.example.edu</a> from the principal on their end so that would save you a step.<div><br>Dave</div></div><div class="gmail_extra">
<br><br><div class="gmail_quote">On Fri, Apr 25, 2014 at 9:32 PM, Rich Graves <span dir="ltr">&lt;<a href="mailto:rgraves@carleton.edu" target="_blank">rgraves@carleton.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Muttering to myself:<br>
<div class="">&gt; Has anyone looked into making (something like) the <a href="http://switch.ch" target="_blank">switch.ch</a> Kerberos authentication plugin work within the MCB framework, in place of the bronze-level username/password?<br>

<br>
</div>Well, I don&#39;t have either working yet, but possible strategies include:<br>
<br>
1) Use the MCB RemoteUser submodule, with /Authn/MCB/RemoteUser protected by mod_auth_kerb. I would need to strip the @<a href="http://AD.EXAMPLE.EDU" target="_blank">AD.EXAMPLE.EDU</a> from the REMOTE_USER variable, but it might work, including Duo second factor as needed.<br>

<br>
2) Use the SWITCH Kerberos module, which I think can be installed in the same server as MCB. Not desirable because it would seem to require each SP to specify context and there&#39;s no possibility of requiring Duo second factor.<br>

<br>
Is #1 a viable strategy?<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br>David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div>
</div>