<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Aug 18, 2015 at 6:30 PM, IAM David Bantz <span dir="ltr"><<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div class="gmail_extra"><span class=""><br><div class="gmail_quote">On Tue, Aug 18, 2015 at 2:34 PM, David Langenberg <span dir="ltr"><<a href="mailto:davel@uchicago.edu" target="_blank">davel@uchicago.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">You must force it to PPT or they will reject it. We wound up tweaking our config to make sure we send PPT rather than Password.</blockquote></div><br></span>Uncle! RelyingParty config with defaultAuthenticationMethod does not force the AuthnContextRefClass to PPT and in any case doesn't address Duo 2FA users.  Please give me a hint on how to "force [AuthnContextRefClass in outgoing SAML] to PPT" for a relying party. Perhaps a clever config in multi-context-broker.xml ?</div></div></blockquote><div><br></div><div>I wish I could show you something cool & clever.  Unfortunately, I had to in the end eliminate Password from anywhere in my configs (only using PPT) and then gave my users a choice.  The distasteful choice was could use <a href="http://research.gov">research.gov</a> or they could be defaulted to 2FA.  Those who were negatively affected chose to opt-out of electing to force Duo.  Now, that said, things seem to work properly under IdPv3 (<a href="http://research.gov">research.gov</a> seems to at least see me).  I'll see if I can track down somebody who uses the site & get them to try Duo.</div><div><br></div><div>Dave</div><div><br></div></div>-- <br><div class="gmail_signature"><div dir="ltr"><div>David Langenberg<div>Identity & Access Management Architect</div><div>The University of Chicago</div></div></div></div>
</div></div>