<div dir="ltr"><br><div class="gmail_extra"><br><br><div class="gmail_quote">On Thu, Aug 21, 2014 at 6:35 AM, Tom Scavo <span dir="ltr"><<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="">On Wed, Aug 20, 2014 at 10:10 PM, Wessel, Keith <<a href="mailto:kwessel@illinois.edu">kwessel@illinois.edu</a>> wrote:<br>
> Where my situation gets tricky is that Duo can't be an initial authentication context. The Duo submodule uses a principal from another submodule. In my case, the only context that can be triggered initially, regardless of what was requested, is password.<br>
<br>
</div>I don't know what Duo module you're referring to (one distributed with<br>
the MCB?) but essentially you're saying the module doesn't support<br>
step-up authentication.<br></blockquote><div><br></div><div>He's referring to the MCB Duo module. The module requires that the user's identity be previously established by another unspecified method before it can be called.</div>
<div><br></div><div>Dave</div></div><div><br></div>-- <br>David Langenberg<div>Identity & Access Management</div><div>The University of Chicago</div>
</div></div>