<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Of course, if you went with #1, you&#8217;d hit upon what I&#8217;m up against: the fact that remote_user can&#8217;t intelligently support things like forced reauthentication&#8230;
 unless you can just have a very short Kerberos ticket lifetime.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D">Keith<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style="font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>David Langenberg<br>
<b>Sent:</b> Friday, April 25, 2014 11:07 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: MCB and Kerberos NEGOTIATE<o:p></o:p></span></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<p class="MsoNormal">1 sounds viable. &nbsp;Duo, I believe, can strip the @<a href="http://ad.example.edu">ad.example.edu</a> from the principal on their end so that would save you a step.<o:p></o:p></p>
<div>
<p class="MsoNormal"><br>
Dave<o:p></o:p></p>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><o:p>&nbsp;</o:p></p>
<div>
<p class="MsoNormal">On Fri, Apr 25, 2014 at 9:32 PM, Rich Graves &lt;<a href="mailto:rgraves@carleton.edu" target="_blank">rgraves@carleton.edu</a>&gt; wrote:<o:p></o:p></p>
<p class="MsoNormal">Muttering to myself:<o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">&gt; Has anyone looked into making (something like) the
<a href="http://switch.ch" target="_blank">switch.ch</a> Kerberos authentication plugin work within the MCB framework, in place of the bronze-level username/password?<o:p></o:p></p>
</div>
<p class="MsoNormal">Well, I don't have either working yet, but possible strategies include:<br>
<br>
1) Use the MCB RemoteUser submodule, with /Authn/MCB/RemoteUser protected by mod_auth_kerb. I would need to strip the @<a href="http://AD.EXAMPLE.EDU" target="_blank">AD.EXAMPLE.EDU</a> from the REMOTE_USER variable, but it might work, including Duo second
 factor as needed.<br>
<br>
2) Use the SWITCH Kerberos module, which I think can be installed in the same server as MCB. Not desirable because it would seem to require each SP to specify context and there's no possibility of requiring Duo second factor.<br>
<br>
Is #1 a viable strategy?<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
<p class="MsoNormal"><br>
<br clear="all">
<o:p></o:p></p>
<div>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class="MsoNormal">-- <br>
David Langenberg<o:p></o:p></p>
<div>
<p class="MsoNormal">Identity &amp; Access Management<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">The University of Chicago<o:p></o:p></p>
</div>
</div>
</div>
</body>
</html>