<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Sat, Aug 1, 2015 at 9:30 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 8/1/15, 10:36 AM, "users on behalf of David Langenberg" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:davel@uchicago.edu">davel@uchicago.edu</a>> wrote:<br>
<br>
>It seems, so far, to be doing exactly what I want.<br>
<br>
</span>That's good news.<br>
<br>
The one thing to bear in mind is that presumably the Duo flow is then overwriting the AuthenticationResult of the Password flow with its own result, which may be ok, but really depends on what's supposed to be in the Java Subject at the end for this kind of composite method.<br></blockquote><div><br></div><div>For us, it doesn't matter what's a the end as far as Subject goes.  From what I've seen everybody comes out the other end on our impl (password/Duo) pretty much identified the same way with their netID as the principal.  </div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
The Password flow will populate the Subject with various things depending on how the password validation is done, so there would be situations potentially where one might be depending on that content (e.g. Kerberos ticket, LDAP result).<br>
<br>
The other thing I was going to mention is that I don't know if it's really all that well-defined what ForceAuthn should mean here to begin with. One could argue that invoking the Duo flow alone is "enough" to satisfy ForceAuthn. That seems like one of those community-established norms that probably doesn't exist right now.<br></blockquote><div><br></div><div>Yes, what forceAuthn means probably needs some fleshing out.  Locally here, what folks assume it means can be best described as "poor man's logout".  When I saw the default behavior, it made sense that only Duo would fire as, well, we know who you are already and we know Duo is what you are only allowed to do, so, we forced you to re-do Duo.  However, we also allow users to check a little box in Duo that says "remember my authN for 30 days" which had the effect of turning the forceAuthn request into (from a user POV) an SSO operation.  I imagine we could turn forceAuthn back into what it should mean once the IdP's logout support improves.</div><div><br></div><div>Dave</div></div><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr"><div>David Langenberg<div>Identity & Access Management Architect</div><div>The University of Chicago</div></div></div></div>
</div></div>