<div dir="ltr"><div class="gmail_default" style="font-family:courier new,monospace">Sorry for the length of this. I'll try and be as terse as possible</div><div class="gmail_default" style="font-family:courier new,monospace"><br></div><div class="gmail_default" style="font-family:courier new,monospace">We are starting to look at implementing Duo MFA (Again). I've been reading the documentation and I think I understand the simple implementation, however what we are proposing to do is bring up some high level questions.</div><div class="gmail_default" style="font-family:courier new,monospace"><br></div><div class="gmail_default" style="font-family:courier new,monospace">An admittingly sledgehammer approach is that we are proposing we perform MFA on every site, however we configure duo to allow bypass if they are not enrolled. That means if you have a duo profile you will be prompted for MFA if the SP doesn't make a specific context ref request. In addition we want to allow users to save their device for some amount of days yet to be defined. I'm not too worried about that one because the SP probably doesn't care if MFA was performed or not.</div><div class="gmail_default" style="font-family:courier new,monospace"><br></div><div class="gmail_default" style="font-family:courier new,monospace">However in looking at the <a href="http://refeeds.org/mfa">refeeds.org/mfa</a> there would undoubtedly be SPs that are interested in the fact an MFA challenge was made. However I'm not sure how that works technically. If MFA is presented and the user does not have a profile, then it may still go through the duo workflow but no MFA is actually performed. It looks like the default way to handle this is to assert that AuthenContextRef is mfa, BUT for someone who doesn't have a profile we shouldn't do that, or did I miss some callback that does define that?</div><div class="gmail_default" style="font-family:courier new,monospace"><br></div><div class="gmail_default" style="font-family:courier new,monospace">Additionally if a device is saved, is that enough to assert MFA? I could see it falling into "something you have" as opposed to "something you do". Obviously "something you do" comes first.</div><div class="gmail_default" style="font-family:courier new,monospace"><br></div><div class="gmail_default" style="font-family:courier new,monospace">The last point is if we do default MFA (where SP doesn't care) and we have the MFA context request does that require different polices do we therefore need multiple duo integrations?</div><div class="gmail_default" style="font-family:courier new,monospace"><br></div><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><font face="monospace, monospace">Jeffrey E. Crawford<br>Enterprise Service Team<a href="mailto:jeffreyc@ucsc.edu" target="_blank"></a></font><div><font face="monospace, monospace">    ^         ^</font></div><div><font face="monospace, monospace">   / \  ^    / \    ^</font></div><div><font face="monospace, monospace">  /   \/ \  /   \  / \</font></div><div><font face="monospace, monospace"> /        \/     \/   \</font></div><div><font face="monospace, monospace">/                      \</font></div><div><font face="monospace, monospace"><br></font></div><div><font face="monospace, monospace">You have been assigned this mountain to prove to others that it *can* be moved.</font></div></div></div></div></div></div></div>
</div>