<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;"><br><div><div>On Aug 21, 2014, at 8:37 AM, David Langenberg &lt;<a href="mailto:davel@uchicago.edu">davel@uchicago.edu</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div dir="ltr"><br><div class="gmail_extra"><br><br><div class="gmail_quote">On Thu, Aug 21, 2014 at 6:35 AM, Tom Scavo <span dir="ltr">&lt;<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="">On Wed, Aug 20, 2014 at 10:10 PM, Wessel, Keith &lt;<a href="mailto:kwessel@illinois.edu">kwessel@illinois.edu</a>&gt; wrote:<br>

&gt; Where my situation gets tricky is that Duo can't be an initial authentication context. The Duo submodule uses a principal from another submodule. In my case, the only context that can be triggered initially, regardless of what was requested, is password.<br>

<br>
</div>I don't know what Duo module you're referring to (one distributed with<br>
the MCB?) but essentially you're saying the module doesn't support<br>
step-up authentication.<br></blockquote><div><br></div><div>He's referring to the MCB Duo module. &nbsp;The module requires that the user's identity be previously established by another unspecified method before it can be called.</div>
<div><br></div><div>Dave</div></div><div><br></div></div></div></blockquote><br></div><div>Wouldn't think it is the MCB Duo module's "fault", because either it gets invoked or not. It comes down to whether the MCB can currently support the full complexity of use cases some deployers are trying.</div><div><br></div><div>If the user had already done password, and the service requesting indicated it only accepted Duo, it will require the user to do Duo. The reported problem seems to come in when the user has already done password as the initial context, and the service will accept either, with Duo listed first. The user is not getting presented the choice to do/"add" Duo.</div><div><br></div><div>Does playing games with the two different password contexts, :Password versus :PasswordProtectedContext, make any difference? Listing :Password for initial context, and then having :PasswordProtectedContext as a later context with the same method, and having the service list :PasswordProtectedContext as the 2nd choice? Probably won't make a difference, since both are satisfied by the same method.</div><div apple-content-edited="true"><span class="Apple-style-span" style="border-collapse: separate; border-spacing: 0px;"><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;  "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;  "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br>--<br>Michael A. Grady<br>Senior IAM Consultant, Unicon, Inc.</div></span></div></span></span>
</div>
<br></body></html>