Yes. You must force it to PPT or they will reject it. We wound up tweaking our config to make sure we send PPT rather than Password. I went several rounds with them a year ago to try to get them to stop requesting unspecified when they really only want PPT,<span></span> but eventually I had to give up. I probably have one year before Duo sufficiently penetrates the faculty and this issue crops up again. <div><br></div><div>Dave<br><br>On Tuesday, August 18, 2015, IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">That's an interesting hint David.  The request received by my IdP has 2 contexts listed in the request:<div>







<p><span><?xml version="1.0" encoding="UTF-8"?><br><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol</span><span> ...></span></p>
<p><span><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://identity" target="_blank">https://identity</a>.</span><span><a href="http://research.gov" target="_blank">research.gov</a></span><span>/sso/sp</saml:Issuer><br></span>...<br><samlp:RequestedAuthnContext Comparison="exact" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><br>    <saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:<b>ac:classes:unspecified</b></saml:AuthnContextClassRef><br>  <saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:<b>ac:classes:PasswordProtectedTransport</b></saml:AuthnContextClassRef><br> </samlp:RequestedAuthnContext><br>...</p><p><span>I'm returning for my own login attempt an indication of MCB/duo in AuthnContextClassRef:</span><br></p><p><span>... <saml2:AuthnStatement ...><br></span>      <saml2:AuthnContext><br>         <saml2:AuthnContextClassRef><b><a href="https://iam.alaska.edu/trac/wiki/mfa" target="_blank">https://iam.alaska.edu/trac/wiki/mfa</a><</b>/saml2:AuthnContextClassRef><br>      </saml2:AuthnContext>...</p><p><span>and for non 2-factor user, I'm returning simply "Password" in AuthnContextClassRef:</span></p><p><span> ...  <saml2:AuthnStatement ...><br></span>      <saml2:SubjectLocality Address="137.229.40.130"/><br>      <saml2:AuthnContext><br>       <saml2:AuthnContextClassRef><b>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</b></saml2:AuthnContextClassRef>      </saml2:AuthnContext>...</p><p>I should be forcing the context to PPT?  <br></p><p>How do I do that for an SP?</p><p>David Bantz</p><p><br></p></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Aug 18, 2015 at 12:48 PM, David Langenberg <span dir="ltr"><<a href="javascript:_e(%7B%7D,'cvml','davel@uchicago.edu');" target="_blank">davel@uchicago.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">What authncontext are you sending to them?  Research.gov has an odd requirement that you must send PPT even though they don't request it. <div><br></div><div>Ave<div><div><span></span><br><br>On Tuesday, August 18, 2015, Kevin Foote <<a href="javascript:_e(%7B%7D,'cvml','kpfoote@uoregon.edu');" target="_blank">kpfoote@uoregon.edu</a>> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><br>
<br>
> On Aug 18, 2015, at 12:51 PM, IAM David Bantz <<a>dabantz@alaska.edu</a>> wrote:<br>
><br>
> We set up federated (via InC) access to NSF and <a href="http://research.gov" target="_blank">research.gov</a> quote a while ago. An email from an NSF contractor 5 Aug requested testing of "new authentication technology" from which I discovered our institution's federated login attmpts now fail with the sole information in the browser "Single Singn On failed"; for all I know this may have been in fail state some time prior to this request and whatever change was made at <a href="http://research.gov" target="_blank">research.gov</a>.<br>
><br>
> Are others experiencing any problems with Shibb-InC federated access to <a href="http://research.gov" target="_blank">research.gov</a> or is it just our IdP?<br>
><br>
> (I'm asking here because over 2 weeks since providing my logs to them showing outgoing SAML assertion, the only responses I've pried from NSF are "reboot your computer and try again" and "are your credentials registered with InCommon?”)<br>
<br>
Hi David,<br>
<br>
I can’t say that I’ve had as much trouble as you.<br>
I acted on the email that you referred to in your message and I got a similar “failed” message. I replied to the said address with the results and heard nothing - still nothing.<br>
However I tried a few days later and all worked.<br>
<br>
AFAIK it is still working as well, no complaints and a few general population logins for the service.<br>
<br>
--------<br>
thanks<br>
 kevin.foote<br>
<br>
--<br>
To unsubscribe from this list send an email to <a>users-unsubscribe@shibboleth.net</a></blockquote></div></div></div><span><font color="#888888"><br><br>-- <br><div dir="ltr"><div>David Langenberg<div>Identity & Access Management Architect</div><div>The University of Chicago</div></div></div><br>
</font></span><br>--<br>
To unsubscribe from this list send an email to <a href="javascript:_e(%7B%7D,'cvml','users-unsubscribe@shibboleth.net');" target="_blank">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>
</blockquote></div><br><br>-- <br><div dir="ltr"><div>David Langenberg<div>Identity & Access Management Architect</div><div>The University of Chicago</div></div></div><br>