<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif;">
<div>
<div>Have you tested logging in to a TFA-required SP first and then a non-TFA SP, and then starting a new browser session and logging in in the opposite order (non-TFA an then TFA)?</div>
<div><br>
</div>
<div>
<div>We tried the exact method that you describe and could not find any way using the MCB to achieve this. It appears to do the right thing if you login TFA first and then non-TFA, but even though the scripted attribute is recalculated on the second login,
 the MCB will only ever use the calculated list of contexts from the first login. The MCB is focused around the user, and really has no concept of the combination of user+SP, which was a hard idea to get our heads around. The use cases assume that once a user
 opts-in or is required to use MFA, then the user will always use MFA on all subsequent logins.</div>
</div>
<div><br>
</div>
<div>
<div id="MAC_OUTLOOK_SIGNATURE">
<div>Thanks,</div>
<div>Mark</div>
<div><br>
</div>
</div>
</div>
</div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="font-family:Calibri; font-size:12pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style="font-weight:bold">From: </span>users on behalf of Rhian Resnick<br>
<span style="font-weight:bold">Reply-To: </span>Shib Users<br>
<span style="font-weight:bold">Date: </span>Monday, October 19, 2015 at 7:40 PM<br>
<span style="font-weight:bold">To: </span>Shib Users<br>
<span style="font-weight:bold">Subject: </span>Re: requiring 2FA for a service (Shibboleth 2 & MCB)<br>
</div>
<div><br>
</div>
<div>
<meta content="text/html; charset=utf-8">
<div style="word-wrap:break-word; color:rgb(0,0,0); font-size:14px; font-family:Calibri,sans-serif">
<span style="font-family:Arial; font-size:12pt">In 2x we use a scripted atrribute to specify the assurance level required by MCB and a specific service provider.
<br>
<br>
Same technique should work in 3x.<br>
<br>
Rhian<br>
FAU</span><span style="font-family:Arial"><br>
<br>
-------- Original Message --------<br>
From:Mark McCoy <br>
Sent:Mon, 19 Oct 2015 18:06:49 -0400<br>
To:Shib Users <br>
Subject:Re: requiring 2FA for a service (Shibboleth 2 & MCB)<br>
<br>
</span>
<div>
<div>
<div>
<div>That was our experience. We did not find a way to force TFA at the IdP side with the MCB, and had to fall back to having the SP require the needed context.</div>
<div>
<div id="">
<div><br>
</div>
<div>Thanks,</div>
<div>Mark</div>
<div><br>
</div>
</div>
</div>
</div>
</div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="font-family:Calibri; font-size:12pt; text-align:left; color:black; border-bottom:medium none; border-left:medium none; padding-bottom:0in; padding-left:0in; padding-right:0in; border-top:#b5c4df 1pt solid; border-right:medium none; padding-top:3pt">
<span style="font-weight:bold">From: </span>users on behalf of Michael A Grady<br>
<span style="font-weight:bold">Reply-To: </span>Shib Users<br>
<span style="font-weight:bold">Date: </span>Thursday, October 15, 2015 at 7:12 PM<br>
<span style="font-weight:bold">To: </span>Shib Users<br>
<span style="font-weight:bold">Subject: </span>Re: requiring 2FA for a service (Shibboleth 2 & MCB)<br>
</div>
<div><br>
</div>
<div>
<div class="" style="word-wrap:break-word">I'm pretty sure that setting in relying-party.xml only got used if the SP did not explicitly request something. If the SP does have an explicit request, that takes precedence.
<div class=""><br class="">
<div>
<blockquote type="cite" class="">
<div class="">On Oct 15, 2015, at 6:49 PM, David Walker <<a href="mailto:dwalker@internet2.edu" class="">dwalker@internet2.edu</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div bgcolor="#FFFFFF" class=""><font size="-1" class="">The current version of the MCB (for Shib 2) should be treating the defaultAuthenticationMethod in relying-party.xml as if it were a context requested by the SP, so if you set that to a context requiring
 MFA, it should do what you want.  What I don't remember (and the GitHub issue below doesn't illuminate) is whether it will override an explicit request from the SP or if it's merely a default when the SP requests no context.  Paul, if you're watching, do you
 remember?<br class="">
<br class="">
By the way, this functionality was not in the initial release; </font><font size="-1" class=""><font size="-1" class="">see
<a href="https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues/11" class="">
</a><a class="moz-txt-link-freetext" href="https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues/11">https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues/11</a> for details. 
</font><br class="">
<br class="">
David<br class="">
<br class="">
</font><br class="">
<div class="moz-cite-prefix">On 10/14/2015 07:02 PM, Cantor, Scott wrote:<br class="">
</div>
<blockquote type="cite" class="">
<pre class="">On 10/14/15, 9:51 PM, "users on behalf of IAM David Bantz" <a class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.netonbehalfofdabantz@alaska.edu"><users-bounces@shibboleth.net on behalf of dabantz@alaska.edu></a> wrote:



</pre>
<blockquote type="cite" class="">
<pre class="">Seems it should be possible, setting the defaultAuthenticationMethod for this service in relying-party.xml
</pre>
</blockquote>
<pre class="">That's nominally correct, but in V2 that isn't really quite saying that it requires that method. That tells it what to do in the absence of any other decision, but it has no way of enforcing what happened before it finishes up. I don't know if the MCB changes that, I guess it probably does.

-- Scott

</pre>
</blockquote>
<br class="">
</div>
-- <br class="">
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">
users-unsubscribe@shibboleth.net</a></div>
</blockquote>
</div>
<br class="">
<div class=""><br class="">
--<br class="">
Michael A. Grady<br class="">
IAM Architect, Unicon, Inc. </div>
<br class="">
</div>
</div>
</div>
</span></div>
</div>
</div>
</span>
</body>
</html>