<div dir="ltr">Try updating.  What it&#39;s supposed to do in that case is require Duo and if the user can&#39;t meet Duo then just fall back to password.<div><br>Dave</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">
On Wed, Aug 20, 2014 at 3:48 PM, Wessel, Keith <span dir="ltr">&lt;<a href="mailto:kwessel@illinois.edu" target="_blank">kwessel@illinois.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">






<div lang="EN-US" link="blue" vlink="purple">
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d">Was hoping you’d chime in since you’ve probably been down this road, Dave.<u></u><u></u></span></p>

<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d">I’m on 1.1.2 which is probably part of my problem. 1.2.0 is the latest stable, correct?<u></u><u></u></span></p>

<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d">When I log in with an SP that specifies no authnContextClassRef then go to my SP that has both listed, duo first, it seems to be honoring my existing password
 authentication and not giving me the chance to move up.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d">Keith<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;">From:</span></b><span style="font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;"> <a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> [mailto:<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>]
<b>On Behalf Of </b>David Langenberg<br>
<b>Sent:</b> Wednesday, August 20, 2014 4:42 PM</span></p><div class=""><br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: MCB with Duo and password as fallback<u></u><u></u></div><p></p><span class="HOEnZb"><font color="#888888">
<p class="MsoNormal"><u></u> <u></u></p>
</font></span><div><span class="HOEnZb"><font color="#888888">
<p class="MsoNormal">Keith,<u></u><u></u></p></font></span><div><div class="h5">
<div>
<p class="MsoNormal"><br>
What happens when you get rid of your dummy class and try to access that SP as the 2nd SP of the session (SSO through to it?).  Also, what version of the MCB are you trying this with?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Dave<u></u><u></u></p>
</div>
</div></div></div><div><div class="h5">
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><u></u> <u></u></p>
<div>
<p class="MsoNormal">On Wed, Aug 20, 2014 at 3:20 PM, Wessel, Keith &lt;<a href="mailto:kwessel@illinois.edu" target="_blank">kwessel@illinois.edu</a>&gt; wrote:<u></u><u></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal">Hi, all,<br>
<br>
We&#39;re getting our plans together to put the MCB and Duo in place, and I&#39;m preparing a demo for our security folks to help us make some decisions.<br>
<br>
I&#39;d like to set up a service provider to require Duo if available and, if not, to settle for username/password. This would allow users from two different assurance levels in that the application could handle accordingly.<br>

<br>
But I&#39;m hitting a snag. With my authnContextClassRef set to the duo context followed by the password context, and my initial context in the MCB set only to password, I get prompted to password authenticate. But then I never get sent to Duo authenticate, presumably
 because I&#39;ve already settled the password context.<br>
<br>
Only solution I can think of is to add a 3rd context which uses the password method that an SP will never ask for and configure it as my only initial context. If a user is eligible for Duo, the MCB will then try to satisfy the Duo context as it already knows
 the user&#39;s principal. If the user is only eligible for password, and since that method has already been satisfied, the password context will be returned to the service provider.<br>
<br>
It feels like a hack to have a 3rd dummy context, though. I was hoping, after doing password authn, the MCB would then see that Duo was preferred and do that. No such luck.<br>
<br>
Is there a cleaner way to do what I&#39;m trying to do?<br>
<br>
Thanks,<br>
Keith<br>
<span style="color:#888888"><br>
<span>--</span><br>
<span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a></span></span><u></u><u></u></p>
</blockquote>
</div>
<p class="MsoNormal"><br>
<br clear="all">
<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<p class="MsoNormal">-- <br>
David Langenberg<u></u><u></u></p>
<div>
<p class="MsoNormal">Identity &amp; Access Management<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">The University of Chicago<u></u><u></u></p>
</div>
</div>
</div></div></div>
</div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br>David Langenberg<div>Identity &amp; Access Management</div>
<div>The University of Chicago</div>
</div>