<div dir="ltr">Perceived need for non-web SSO login with Duo 2FA to AWS [I'm assured not all AWS services are available from the web admin interface] is pushing us to deploy ECP, not currently in use here. I'm puzzled by two different descriptions of deploying:<br><br><div><a href="https://wiki.shibboleth.net/confluence/display/IDP30/ECPConfiguration" target="_blank" style="font-size:12.8px">https://wiki.shibboleth.net/<wbr>confluence/display/IDP30/<wbr>ECPConfiguration</a> looked straightforward at first glance provided the JAAS authN configuration can be different than the JAAS config used for "normal" web-based (we'd point to Duo proxy to get 2FA for ECP).<br></div><div><br></div><div>But then a guru suggested we need to base configuration on RemoteUser:</div><div><a href="https://wiki.shibboleth.net/confluence/display/IDP30/RemoteUserInternalAuthnConfiguration" target="_blank" style="font-size:12.8px">https://wiki.shibboleth.net/<wbr>confluence/display/IDP30/<wbr>RemoteUserInternalAuthnConfigu<wbr>ration</a><br></div><div>which is sufficiently generic I don't know where to begin.</div><div><br></div><div>Where do I begin? What are the major tasks needed to deploy ECP (with Duo Proxy).?</div><div><br></div><div>David Bantz</div></div>