<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" dir="ltr">
<p><font face="Calibri, Arial, Helvetica, sans-serif"><span style="font-size: 12pt;">Thanks for clearing up the util list values as we were having similar troubles with it, good timing. </span></font><font face="Calibri, Arial, Helvetica, sans-serif"><span style="font-size: 12pt;">We
are also trying to use Multiple Integrations with distinct principle sets and are running into an issue</span></font><font face="Calibri, Arial, Helvetica, sans-serif"><span style="font-size: 12pt;">. We can call duo for individual integrations</span></font><font face="Calibri, Arial, Helvetica, sans-serif"><span style="font-size: 12pt;"> based
on authncontextclassRef for the </span></font><font face="Calibri, Arial, Helvetica, sans-serif"><span style="font-size: 12pt;">initial mfa calling to Duo. However, when changing authncontextclassRef profiles and trying to reuse the mfa result it is never
getting to authn to evaluate the profile giving an error of NoAuthnContext. Reading the documentation on MultiFactorAuthnConfiguration in the Single Sign-On / Reuse section it appears that we are meeting the requirements but obviously we are missing something.</span></font></p>
<p><span style="font-size: 12pt;"><br>
</span></p>
<p><font face="Calibri, Arial, Helvetica, sans-serif"><span style="font-size: 12pt;"></span></font><span style="font-size: 12pt;"></span></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">
</p>
<div>2017-01-09 16:04:23,732 - DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:214] - Profile Action TransitionMultiFactorAuthentication: MFA flow transition after 'proceed' event to 'authn/Duo' flow</div>
<div>2017-01-09 16:04:23,732 - DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:262] - Profile Action TransitionMultiFactorAuthentication: Reusing active result for 'authn/Duo' flow</div>
<div>2017-01-09 16:04:23,732 - DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:197] - Profile Action TransitionMultiFactorAuthentication: Applying MFA transition rule to exit state 'authn/Duo'</div>
<div>2017-01-09 16:04:23,732 - DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:219] - Profile Action TransitionMultiFactorAuthentication: MFA flow completing with event 'proceed'</div>
<div>2017-01-09 16:04:23,779 - WARN [net.shibboleth.idp.authn.impl.FinalizeAuthentication:179] - Profile Action FinalizeAuthentication: Authentication result for flow authn/MFA did not satisfy the request</div>
<div>2017-01-09 16:04:23,810 - WARN [org.opensaml.profile.action.impl.LogEvent:105] - A non-proceed event occurred while processing the request: RequestUnsupported</div>
<div><br>
</div>
Thanks,
<p></p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">
Paul M</p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">
<br>
</p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">
<br>
</p>
<p style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">
<br>
</p>
<div dir="ltr" style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Arial,Helvetica,sans-serif">
<p class="x_MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(33, 33, 33);">
<span style="color: rgb(31, 56, 100);"></span></p>
<br>
<p></p>
<p><br>
</p>
<p><br>
</p>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Scott Koranda <skoranda@gmail.com><br>
<b>Sent:</b> Monday, January 9, 2017 2:58:54 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Multiple Duo Integrations with distinct principal sets</font>
<div> </div>
</div>
</div>
<font size="2" style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;"><span style="font-size:10pt;">
<div class="PlainText">> > I do not understand how a null context object is<br>
> > happening.<br>
> <br>
> I'm just guessing, but the example script I showed returns<br>
> null if it doesn't find a Duo configuration that "satisfies"<br>
> the request. I think that it must be exhausting the possible<br>
> cases without finding one, and if that was an actual<br>
> possibility, I don't think the general approach here would<br>
> work right.<br>
<br>
Sigh. It was, of course, exhausting the possible cases because<br>
I had a typo in the principal string for one of the beans. I<br>
should really define them once and reference them...<br>
<br>
Sorry for the noise. The multiple Duo integration/flow works<br>
as expected.<br>
<br>
I updated the wiki page with the syntax for the <util:list><br>
that works.<br>
<br>
Thanks,<br>
<br>
Scott K<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
<span style="font-size:10.0pt;font-family:"Arial","sans-serif""><o:p></o:p></span>
<p></p>
<div></div>
<p class="MsoNormal"><o:p> </o:p></p>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="100%" align="center">
</div>
<p class="MsoNormal"><span style="font-size:7.5pt;font-family:"Arial","sans-serif";color:gray">The materials in this message are private and may contain Protected Healthcare Information or other information of a sensitive nature. If you are not the intended
recipient, be advised that any unauthorized use, disclosure, copying or the taking of any action in reliance on the contents of this information is strictly prohibited. If you have received this email in error, please immediately notify the sender via telephone
or return mail.</span></p>
</body>
</html>