<div dir="ltr">In the relying-party.xml config for the SP I want to use 2FA,<div>I set defaultAuthenticationMethod to designate our Duo 2FA context rather than usual PPT:<div><br></div><div>from:</div><div>    <span class="">defaultAuthenticationMethod</span><span class="">=</span><span class="">"urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport"</span></div><div><span class="">to:</span></div><div><span class="">    </span><span class="">defaultAuthenticationMethod</span><span class="">=</span><span class="">"<a href="https://iam.alaska.edu/trac/wiki/mfa">https://iam.alaska.edu/trac/wiki/mfa</a>"</span></div><div><span class=""><br></span></div><div><span class="">Unfortunately, users not explicitly provisioned Duo 2FA context simply authenticate with password instead.</span></div><div><span class=""><br></span></div><div><span class="">Is there some MFB configuration that could avoid that - could enforce 2FA or deny if the user cannot use 2FA?</span></div><div><span class=""><br></span></div><div><span class="">[AWS alas is accessed via unsolicited SSO request.  While I can write the request to ask for 2FA context, it would of course be trivial for someone to write their own request dropping that part of the request and thus gain access with just PPT.  So I need some way of</span></div><div><span class="">enforcing use of 2FA. If I cannot do that with some combination of metadata, relying-party, and mcb configuration, I'm thinking I </span></div><div><span class="">could conditionally release required attributes based on AuthenticationMethodString in the attribute-filter.xml; that would drop the user into an AWS session, but with no roles to accomplish anything.]</span></div><div><span class=""><br></span></div><div><span class="">David Bantz</span></div>















</div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Oct 15, 2015 at 4:13 PM, Paul Caskey <span dir="ltr"><<a href="mailto:pcaskey@internet2.edu" target="_blank">pcaskey@internet2.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div bgcolor="white" lang="EN-US" link="blue" vlink="purple">
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d">We never got the method of setting defaultAuthenticationMethod in relying-party.xml to work correctly (even with what we thought was the latest version), so
 I can’t say for sure.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><u></u> <u></u></span></p>
<div style="border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt">
<div>
<div style="border:none;border-top:solid #b5c4df 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:windowtext">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:windowtext"> users [mailto:<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>]
<b>On Behalf Of </b>David Walker<br>
<b>Sent:</b> Thursday, October 15, 2015 6:50 PM<br>
<b>To:</b> <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
<b>Subject:</b> Re: requiring 2FA for a service (Shibboleth 2 & MCB)<u></u><u></u></span></p>
</div>
</div><div><div class="h5">
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-size:10.0pt">The current version of the MCB (for Shib 2) should be treating the defaultAuthenticationMethod in relying-party.xml as if it were a context requested by the SP, so if you set that
 to a context requiring MFA, it should do what you want.  What I don't remember (and the GitHub issue below doesn't illuminate) is whether it will override an explicit request from the SP or if it's merely a default when the SP requests no context.  Paul, if
 you're watching, do you remember?<br>
<br>
By the way, this functionality was not in the initial release; see <a href="https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues/11" target="_blank">
https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues/11</a> for details. 
<br>
<br>
David<br>
<br>
</span><u></u><u></u></p>
<div>
<p class="MsoNormal">On 10/14/2015 07:02 PM, Cantor, Scott wrote:<u></u><u></u></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<pre>On 10/14/15, 9:51 PM, "users on behalf of IAM David Bantz" <a href="mailto:users-bounces@shibboleth.netonbehalfofdabantz@alaska.edu" target="_blank"><users-bounces@shibboleth.net on behalf of dabantz@alaska.edu></a> wrote:<u></u><u></u></pre>
<pre><u></u> <u></u></pre>
<pre><u></u> <u></u></pre>
<pre><u></u> <u></u></pre>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<pre>Seems it should be possible, setting the defaultAuthenticationMethod for this service in relying-party.xml<u></u><u></u></pre>
</blockquote>
<pre><u></u> <u></u></pre>
<pre>That's nominally correct, but in V2 that isn't really quite saying that it requires that method. That tells it what to do in the absence of any other decision, but it has no way of enforcing what happened before it finishes up. I don't know if the MCB changes that, I guess it probably does.<u></u><u></u></pre>
<pre><u></u> <u></u></pre>
<pre>-- Scott<u></u><u></u></pre>
<pre><u></u> <u></u></pre>
</blockquote>
<p class="MsoNormal"><u></u> <u></u></p>
</div></div></div>
</div>
</div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div></div>