<div dir="ltr">Perhaps with some provisos. I have been unable to find a combination of configurations with MCB that will enable an acceptable (by the SP) response to a request with:<div><br></div><div><span style="font-size:12.8px"><<span class="">saml</span>:Issuer xmlns:<span class="">saml</span>="urn:oasis:names:tc:<span class="">SAML</span>:2.0:assertion"><a href="https://identity/" target="_blank">https://identity</a>.</span><span style="font-size:12.8px"><a href="http://research.gov/" target="_blank">research.gov</a></span><span style="font-size:12.8px">/sso/sp</<span class="">saml</span>:Issuer><br></span><span style="font-size:12.8px">...</span><br style="font-size:12.8px"><span style="font-size:12.8px"><samlp:RequestedAuthnContext Comparison="exact" xmlns:samlp="urn:oasis:names:</span><span style="font-size:12.8px">tc:</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">SAML</span><span style="font-size:12.8px">:2.0:protocol"></span><br style="font-size:12.8px"><span style="font-size:12.8px">    <</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">saml</span><span style="font-size:12.8px">:AuthnContextClassRef xmlns:</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">saml</span><span style="font-size:12.8px">="urn:oasis:names:</span><span style="font-size:12.8px">tc:</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">SAML</span><span style="font-size:12.8px">:2.0:assertion">urn:</span><span style="font-size:12.8px">oasis:names:tc:</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">SAML</span><span style="font-size:12.8px">:2.0:</span><b style="font-size:12.8px">ac:classes:unspecified</b><span style="font-size:12.8px"></</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">saml</span><span style="font-size:12.8px">:</span><span style="font-size:12.8px">AuthnContextClassRef></span><br style="font-size:12.8px"><span style="font-size:12.8px">  <</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">saml</span><span style="font-size:12.8px">:AuthnContextClassRef xmlns:</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">saml</span><span style="font-size:12.8px">="urn:oasis:names:</span><span style="font-size:12.8px">tc:</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">SAML</span><span style="font-size:12.8px">:2.0:assertion">urn:</span><span style="font-size:12.8px">oasis:names:tc:</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">SAML</span><span style="font-size:12.8px">:2.0:</span><b style="font-size:12.8px">ac:classes:PasswordProtectedTransport</b><span style="font-size:12.8px"></</span><span class="" style="font-size:12.8px;background-color:rgb(255,255,255)">saml</span><span style="font-size:12.8px">:AuthnContextClassRef></span><br style="font-size:12.8px"><span style="font-size:12.8px"> </samlp:</span><span style="font-size:12.8px">RequestedAuthnContext></span><br style="font-size:12.8px"></div><div><span style="font-size:12.8px"><br></span></div><div><span style="font-size:12.8px">David Bantz</span></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Dec 18, 2015 at 2:21 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> We are all pretty much on the same setup of shibboleth idp 2.5.4, mcb 1.2.5<br>
> and the latest duo mcb plugin cant recall version atm. "we've been told in the<br>
> past custom relying party's to request a specific authcontext was not<br>
> workable in v2x. our deadline for this solution would be before all our<br>
> campus's could all get to idp v3 as well.<br>
<br>
</span>I can only speak to V2 alone, and it supports SP-specific defaulting of an authentication method just fine.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>