<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;background-color:#FFFFFF;font-family:Calibri,Arial,Helvetica,sans-serif;">
<p>If you could describe forcing the response authcontext for a specific user that would be great or point me to the correct wiki article I would appreciate it.</p>
<p><br>
</p>
<p>My Google searching is turning up nothing.  </p>
<p><br>
</p>
<div id="Signature">
<div id="divtagdefaultwrapper" style="background-color:rgb(255,255,255)">
<div name="divtagdefaultwrapper" style="margin:0px">
<div style="background-color:rgb(255,255,255)">
<p class="x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Rhian Resnick</span></p>
<p class="x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:16px; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Assistant Director Middleware and HPC</span><span style="color:black; font-family:Calibri,sans-serif; font-size:11pt"></span></p>
<p class="x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:16px; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Office of Information Technology</span></p>
<p class="x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt"><br>
</span></p>
<p class="x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Florida Atlantic University</span><span style="color:black; font-family:Calibri,sans-serif; font-size:11pt"></span></p>
<p class="x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">777 Glades Road, CM22, Rm 218</span><span style="color:black; font-family:Calibri,sans-serif; font-size:11pt"></span></p>
<p class="x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Boca Raton, FL 33431</span><span style="color:black; font-family:Calibri,sans-serif; font-size:11pt"></span></p>
<p class="x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Phone 561.297.2647</span><span style="color:black; font-family:Calibri,sans-serif; font-size:11pt"></span></p>
<p class="x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt">Fax 561.297.0222</span></p>
<p class="x_MsoNormal" style="color:rgb(33,33,33); font-family:'Times New Roman',serif; font-size:12pt; margin:0in 0in 0pt; background-color:rgb(255,255,255)">
<span style="color:black; font-family:Calibri,sans-serif; font-size:10.5pt"> </span><span style="color:rgb(31,73,125); font-family:Calibri,sans-serif; font-size:11pt"><a href="https://hpc.fau.edu/wp-content/uploads/2015/01/image.jpg" style="border:0px; font-family:Arial,Helvetica,sans-serif; font-size:13px; line-height:21px; margin:0px; padding:0px; vertical-align:baseline; color:rgb(0,102,204); text-decoration:none; background-color:rgb(239,239,239)"></a></span></p>
</div>
</div>
</div>
</div>
<br>
<br>
<div style="color: rgb(0, 0, 0);">
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of David Langenberg <davel@uchicago.edu><br>
<b>Sent:</b> Tuesday, August 18, 2015 6:34 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: issue with research.gov ?</font>
<div> </div>
</div>
<div>Yes. You must force it to PPT or they will reject it. We wound up tweaking our config to make sure we send PPT rather than Password. I went several rounds with them a year ago to try to get them to stop requesting unspecified when they really only want
 PPT,<span></span> but eventually I had to give up. I probably have one year before Duo sufficiently penetrates the faculty and this issue crops up again. 
<div><br>
</div>
<div>Dave<br>
<br>
On Tuesday, August 18, 2015, IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex; border-left:1px #ccc solid; padding-left:1ex">
<div dir="ltr">That's an interesting hint David.  The request received by my IdP has 2 contexts listed in the request:
<div>
<p><span><?xml version="1.0" encoding="UTF-8"?><br>
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol</span><span> ...></span></p>
<p><span><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://identity" target="_blank">https://identity</a>.</span><span><a href="http://research.gov" target="_blank">research.gov</a></span><span>/sso/sp</saml:Issuer><br>
</span>...<br>
<samlp:RequestedAuthnContext Comparison="exact" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><br>
    <saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:<b>ac:classes:unspecified</b></saml:AuthnContextClassRef><br>
  <saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:<b>ac:classes:PasswordProtectedTransport</b></saml:AuthnContextClassRef><br>
 </samlp:RequestedAuthnContext><br>
...</p>
<p><span>I'm returning for my own login attempt an indication of MCB/duo in AuthnContextClassRef:</span><br>
</p>
<p><span>... <saml2:AuthnStatement ...><br>
</span>      <saml2:AuthnContext><br>
         <saml2:AuthnContextClassRef><b><a href="https://iam.alaska.edu/trac/wiki/mfa" target="_blank">https://iam.alaska.edu/trac/wiki/mfa</a><</b>/saml2:AuthnContextClassRef><br>
      </saml2:AuthnContext>...</p>
<p><span>and for non 2-factor user, I'm returning simply "Password" in AuthnContextClassRef:</span></p>
<p><span> ...  <saml2:AuthnStatement ...><br>
</span>      <saml2:SubjectLocality Address="137.229.40.130"/><br>
      <saml2:AuthnContext><br>
       <saml2:AuthnContextClassRef><b>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</b></saml2:AuthnContextClassRef>      </saml2:AuthnContext>...</p>
<p>I should be forcing the context to PPT?  <br>
</p>
<p>How do I do that for an SP?</p>
<p>David Bantz</p>
<p><br>
</p>
</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Tue, Aug 18, 2015 at 12:48 PM, David Langenberg <span dir="ltr">
<<a href="" target="_blank">davel@uchicago.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex; border-left:1px #ccc solid; padding-left:1ex">
What authncontext are you sending to them?  Research.gov has an odd requirement that you must send PPT even though they don't request it. 
<div><br>
</div>
<div>Ave
<div>
<div><span></span><br>
<br>
On Tuesday, August 18, 2015, Kevin Foote <<a href="" target="_blank">kpfoote@uoregon.edu</a>> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex; border-left:1px #ccc solid; padding-left:1ex">
<br>
<br>
> On Aug 18, 2015, at 12:51 PM, IAM David Bantz <<a>dabantz@alaska.edu</a>> wrote:<br>
><br>
> We set up federated (via InC) access to NSF and <a href="http://research.gov" target="_blank">
research.gov</a> quote a while ago. An email from an NSF contractor 5 Aug requested testing of "new authentication technology" from which I discovered our institution's federated login attmpts now fail with the sole information in the browser "Single Singn
 On failed"; for all I know this may have been in fail state some time prior to this request and whatever change was made at
<a href="http://research.gov" target="_blank">research.gov</a>.<br>
><br>
> Are others experiencing any problems with Shibb-InC federated access to <a href="http://research.gov" target="_blank">
research.gov</a> or is it just our IdP?<br>
><br>
> (I'm asking here because over 2 weeks since providing my logs to them showing outgoing SAML assertion, the only responses I've pried from NSF are "reboot your computer and try again" and "are your credentials registered with InCommon?”)<br>
<br>
Hi David,<br>
<br>
I can’t say that I’ve had as much trouble as you.<br>
I acted on the email that you referred to in your message and I got a similar “failed” message. I replied to the said address with the results and heard nothing - still nothing.<br>
However I tried a few days later and all worked.<br>
<br>
AFAIK it is still working as well, no complaints and a few general population logins for the service.<br>
<br>
--------<br>
thanks<br>
 kevin.foote<br>
<br>
--<br>
To unsubscribe from this list send an email to <a>users-unsubscribe@shibboleth.net</a></blockquote>
</div>
</div>
</div>
<span><font color="#888888"><br>
<br>
-- <br>
<div dir="ltr">
<div>David Langenberg
<div>Identity & Access Management Architect</div>
<div>The University of Chicago</div>
</div>
</div>
<br>
</font></span><br>
--<br>
To unsubscribe from this list send an email to <a href="" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote>
</div>
<br>
</div>
</blockquote>
</div>
<br>
<br>
-- <br>
<div dir="ltr">
<div>David Langenberg
<div>Identity & Access Management Architect</div>
<div>The University of Chicago</div>
</div>
</div>
<br>
</div>
</div>
</div>
</body>
</html>