<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">I'm pretty sure that setting in relying-party.xml only got used if the SP did not explicitly request something. If the SP does have an explicit request, that takes precedence.<div class=""><br class=""><div><blockquote type="cite" class=""><div class="">On Oct 15, 2015, at 6:49 PM, David Walker <<a href="mailto:dwalker@internet2.edu" class="">dwalker@internet2.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class="">
  
    <meta content="text/html; charset=windows-1252" http-equiv="Content-Type" class="">
  
  <div bgcolor="#FFFFFF" text="#000000" class="">
    <font size="-1" class="">The current version of the MCB (for Shib 2) should
      be treating the defaultAuthenticationMethod in relying-party.xml
      as if it were a context requested by the SP, so if you set that to
      a context requiring MFA, it should do what you want.  What I don't
      remember (and the GitHub issue below doesn't illuminate) is
      whether it will override an explicit request from the SP or if
      it's merely a default when the SP requests no context.  Paul, if
      you're watching, do you remember?<br class="">
      <br class="">
      By the way, this functionality was not in the initial release; </font><font size="-1" class=""><font size="-1" class="">see <a href="https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues/11" class=""></a><a class="moz-txt-link-freetext" href="https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues/11">https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues/11</a>
        for details.  </font><br class="">
      <br class="">
      David<br class="">
      <br class="">
    </font><br class="">
    <div class="moz-cite-prefix">On 10/14/2015 07:02 PM, Cantor, Scott
      wrote:<br class="">
    </div>
    <blockquote cite="mid:FB2FB3B8-BDA3-42A5-AA1F-4C4F77B960DA@osu.edu" type="cite" class="">
      <pre wrap="" class="">On 10/14/15, 9:51 PM, "users on behalf of IAM David Bantz" <a class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.netonbehalfofdabantz@alaska.edu"><users-bounces@shibboleth.net on behalf of dabantz@alaska.edu></a> wrote:



</pre>
      <blockquote type="cite" class="">
        <pre wrap="" class="">Seems it should be possible, setting the defaultAuthenticationMethod for this service in relying-party.xml
</pre>
      </blockquote>
      <pre wrap="" class="">That's nominally correct, but in V2 that isn't really quite saying that it requires that method. That tells it what to do in the absence of any other decision, but it has no way of enforcing what happened before it finishes up. I don't know if the MCB changes that, I guess it probably does.

-- Scott

</pre>
    </blockquote>
    <br class="">
  </div>

-- <br class="">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">users-unsubscribe@shibboleth.net</a></div></blockquote></div><br class=""><div class="">
<br class="">--<br class="">Michael A. Grady<br class="">IAM Architect, Unicon, Inc.

</div>

<br class=""></div></body></html>