<div dir="ltr"><br><div class="gmail_extra"><br><br><div class="gmail_quote">On Thu, Aug 21, 2014 at 6:35 AM, Tom Scavo <span dir="ltr">&lt;<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="">On Wed, Aug 20, 2014 at 10:10 PM, Wessel, Keith &lt;<a href="mailto:kwessel@illinois.edu">kwessel@illinois.edu</a>&gt; wrote:<br>

&gt; Where my situation gets tricky is that Duo can&#39;t be an initial authentication context. The Duo submodule uses a principal from another submodule. In my case, the only context that can be triggered initially, regardless of what was requested, is password.<br>

<br>
</div>I don&#39;t know what Duo module you&#39;re referring to (one distributed with<br>
the MCB?) but essentially you&#39;re saying the module doesn&#39;t support<br>
step-up authentication.<br></blockquote><div><br></div><div>He&#39;s referring to the MCB Duo module.  The module requires that the user&#39;s identity be previously established by another unspecified method before it can be called.</div>
<div><br></div><div>Dave</div></div><div><br></div>-- <br>David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div>
</div></div>