<div dir="ltr">Because AFAIK the vended SP knows nothing about authN context - certainly not our locally defined 2FA class.<div><br></div><div>David</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Oct 4, 2016 at 11:29 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> [2016-10-04 21:18]:<br>
<span class="">> I think it should be possible to configure a relying party to require a 2FA<br>
> authN context or method, presumably in relying-party.xml but perhaps in the<br>
> local copy of metadata for the SP, but I've been unable to locate correct<br>
> syntax.<br>
<br>
</span>Is the SP requesting an authentication context class?<br>
If not, why not?<br>
<span class="HOEnZb"><font color="#888888">-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br></div>