<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div>
<div>UF is also using a Unicon version.  That we upgraded a few days before Christmas.  Initial testing was successful.  We will be doing a full feature test next week. 
</div>
<div>We were having issues with forced auth in version 3.1..  Moved to 3.21 with a reasonable straight forward process. Unicon provided us some insight that saved time.  
</div>
<div><br>
</div>
<div>We are handling 2 distinct Duo contexts, Bronze, and password protected.  We were seeing some issues with the handling of unspecified.   This will be shaken out in the next set of testing.
</div>
<div><br>
</div>
<div><font style="color:#333333"><i>Sent from my Verizon Wireless 4G LTE DROID</i></font></div>
</div>
<div class="elided-text">On Dec 31, 2015 1:21 PM, Rich Graves <rgraves@carleton.edu> wrote:<br type="attribution">
<blockquote class="quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div><font size="2"><span style="font-size:10pt"></span></font>
<div>> As for 3.2. I've been testing the Unicon module with 3.2 on latest Jetty, and aside from a minor issue with Duo.vm not handling $requestContext properly, it seems to work just fine.
<br>
<br>
Hmm, maybe I'll try it again. The instructions didn't exactly apply, as some paths have changed.<br>
<br>
I'm also giving the Duo package a try. It has some nice fail-safe behavior (shib-mfa-duo-auth issue #9). It doesn't do authentication contexts as "correctly" as Unicon's version, so I could not make specific SPs demand Duo (or Gold/Silver), but I don't currently
 need that feature. All I really want is to be able to toggle Duo on and off with a per-user LDAP attribute, which looks doable either at the Spring level or by injecting the LDAP call into their DuoShibboleth.java.<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</div>
</blockquote>
</div>
</body>
</html>