<div dir="ltr">It sorta mimics how the Duo plugin works, but for your case, I think you&#39;ll have to write your own OTP plug-in so that the proper lookup can be performed (either directly in LDAP or using the attribute-resolver).  The Duo plug-in just reads the principal as reported to it by the MCB proper and passes that along to Duo.<div>
<br></div><div>Dave</div><div><br></div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Wed, May 21, 2014 at 9:01 AM, Mike Wiseman <span dir="ltr">&lt;<a href="mailto:mike.wiseman@utoronto.ca" target="_blank">mike.wiseman@utoronto.ca</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-CA" link="#0563C1" vlink="#954F72">
<div>
<p class="MsoNormal">Hi,<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">I have a somewhat complex use case for the Multi Context Broker and was wondering if anyone has advice on it.
<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">The relying party requires username/password for all applications and OTP for a subset. The username is different from the institutional username so a separate idp that works with the RP environment will be deployed. The OTP service uses
 the institutional username only. So the idp/MCB needs to handle the RP-related username, look up the institutional username and then offer an OTP login to the user. Will MCB keep track of the RP-related username? Can the LDAP lookup be done before the OTP
 login? <u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">This sounds a bit similar to the Duo plugin, does it not?<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Thanks,<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Mike <u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><span>Mike Wiseman<u></u><u></u></span></p>
<p class="MsoNormal"><span>Manager, Information Security<u></u><u></u></span></p>
<p class="MsoNormal"><span>Information Technology Services<u></u><u></u></span></p>
<p class="MsoNormal"><span>University of Toronto<u></u><u></u></span></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<p class="MsoNormal"><span>This email and any attachments contain privileged and / or confidential information for internal University of Toronto communication only unless otherwise indicated.<u></u><u></u></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br>David Langenberg<div>Identity &amp; Access Management</div>
<div>The University of Chicago</div>
</div>