<div dir="ltr"><div><div><div><div><div><div><div><div><div><div><div><div>Hello everyone,<br><br></div>I have installed and configured IdP 3.3 and got it tested against TestShib with the LDAP Username and Password validation flow. All good for know, very nice documentation btw :)<br><br></div><div>This is what I need help at:<br></div>I want to implement the following authn flow:<br></div>1) the login window presents the user with a challenge: PIN/QR code (this could be a webview to an external server)<br></div>2) the user inputs/scans the code with a mobile app on his <b>personal</b> phone<br></div>3) the users completes the authn flow on his phone and reports to the external server<br></div>    * meanwhile the IdP session polls the external server for authn status (maybe the server can push the result to IdP)<br></div>4) the IdP AuthenticationContext is updated with the AuthenticationResult <b>and</b> the Subject<br><br></div>Note that compared to the duo second factor implementation the Subject is not filled by a previous authn flow it is filled together with the AuthenticationResult by this flow, as the mobile app is registered to a Subject on the external server.<br><br></div>What do you think about that?<br></div>I must admit I am stumped and I think I need  some help from the developers on that.<br>Where should I dig for clues?<br><br><br></div><div>Thank you shibboleth community!<br></div></div></div>