<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Jul 31, 2015 at 4:59 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 7/31/15, 6:53 PM, "users on behalf of David Langenberg" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:davel@uchicago.edu">davel@uchicago.edu</a>> wrote:<br>
><br>
>Yeah, we don't want to do that as it would lead to a user having to enter their password twice to authenticate (once for the initial flow & once for the Duo flow).<br>
<br>
</span>That's a function of how one implements such a flow, and that isn't how one would want to implement it.<br>
<br>
In this particular case, though, I would argue this is a bug in the Duo flow in the sense that if it's going to "support" ForceAuthn, it needs to look for this case and either fail, or somehow get the Password flow to run. That's a cost to a strategy of not handling the password half itself.<br></blockquote><div><br></div><div>Looks like I'm going to be learning more about SWF this weekend. </div><div><br></div><div>Thanks,</div><div><br>Dave</div><div><br></div><div> </div></div>-- <br><div class="gmail_signature"><div dir="ltr"><div>David Langenberg<div>Identity & Access Management Architect</div><div>The University of Chicago</div></div></div></div>
</div></div>