<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Aug 18, 2015 at 2:34 PM, David Langenberg <span dir="ltr"><<a href="mailto:davel@uchicago.edu" target="_blank">davel@uchicago.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">You must force it to PPT or they will reject it. We wound up tweaking our config to make sure we send PPT rather than Password.</blockquote></div><br>Uncle! RelyingParty config with defaultAuthenticationMethod does not force the AuthnContextRefClass to PPT and in any case doesn't address Duo 2FA users.  Please give me a hint on how to "force [AuthnContextRefClass in outgoing SAML] to PPT" for a relying party. Perhaps a clever config in multi-context-broker.xml ?</div><div class="gmail_extra"><br></div><div class="gmail_extra">db</div>







</div>