<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Nov 15, 2017 at 10:16 AM, Michael O Holstein <span dir="ltr"><<a href="mailto:michael.holstein@csuohio.edu" target="_blank">michael.holstein@csuohio.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">




<div dir="ltr">
<div id="m_-4641350324927119200divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif" dir="ltr">
2nd on LinOTP.
<div>Caveat : AFIK there's no official (as in from-the-authors) commercial support to make your execs happy.<br></div></div></div></blockquote><div><br></div><div>For LinOTP?  There's absolutely paid support from the authors.  And if one's willing to pay -- as we are -- you can use their "Smart Virtual Appliance" and get most all of the setup and HA as part of the package.  And for Windows, they license a Credential Provider that integrates with the server, which is what we use for our AD logins.</div><div><br></div><div>Greg</div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div id="m_-4641350324927119200divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif" dir="ltr"><div>
<div><br>
</div>
<div>But LinOTP supports all sorts of stuff .. you can do generic HTOP (eg: Google/Microsoft Authentication with self-enroll or any other one) .. TTOP tokens (RSA like, a company called Feltian(*) makes them for ~$6/ea in 10 lot, way cheaper in higher qty,
 and offers a programmer so you can load you own keys) .. plus all sorts of SMS integration (use Twillio).
<div><br>
</div>
<div>It's a tricky bastard to configure and you've got to work out load balancing on your own (and really question why you'd do this on-prem anyway .. just deploy with docker and let $IaaS_Provider do GSLB .. and then a pair of Sambas+OpenLDAP (if you need
 it) as BDCs in a separate VPC to handle the passwords.</div>
<div><br>
</div>
<div>As for backing the thing up, certainly do hot/hot on the MySQL or something similar .. and then call via the API a command to dump the table through a key supplied through the API-to-shell command, and stick the result on another volume which you then
 detach (because that is all sorts of sensitive).</div>
<div><br>
</div>
<div>If you have a VPN I suppose it makes sense to have a local one, you can frontend RADIUS as a protocol. FWIW you can also shim RADIUS into MSGINA if you want to do actual PCs with MFA also.</div>
<div><br>
</div>
<div>As a bonus, this will also backup your domain authentication bits and LDAP structure in a 2nd way that doesn't involve nearly as long of a restore-to-usable as the Microsoft way. Just bring up your replica locally and repoint DNS.</div>
<div><br>
</div>
<div>My $0.0000015 BTC anyway.</div>
<div><br>
</div>
<div>Michael Holstein CISSP</div>
<div>Mgr. Network & Data Security</div>
<div>Cleveland State University</div>
<div><br>
</div>
<div>(*) : <a href="http://www.ftsafe.com/product/onlineShop" class="m_-4641350324927119200OWAAutoLink" id="m_-4641350324927119200LPlnk922670" target="_blank">http://www.ftsafe.com</a></div>
<div id="m_-4641350324927119200LPBorder_GT_15107697638210.4680165553625686" style="margin-bottom:20px;overflow:auto;width:100%;text-indent:0px">
<table id="m_-4641350324927119200LPContainer_15107697638140.1480613621997766" cellspacing="0" style="width:90%;background-color:rgb(255,255,255);overflow:auto;padding-top:20px;padding-bottom:20px;margin-top:20px;border-top:1px dotted rgb(200,200,200);border-bottom:1px dotted rgb(200,200,200)">
<tbody>
<tr valign="top" style="border-spacing:0px">
<td id="m_-4641350324927119200ImageCell_15107697638160.5228184024867735" colspan="1" style="width:250px;display:table-cell;padding-right:20px">
<div id="m_-4641350324927119200LPImageContainer_15107697638160.9178840545260616" style="background-color:rgb(255,255,255);height:135px;margin:auto;display:table;width:250px">
<a id="m_-4641350324927119200LPImageAnchor_15107697638170.9673548418134821" href="http://www.ftsafe.com/product/onlineShop" style="display:table-cell;text-align:center" target="_blank"><img id="m_-4641350324927119200LPThumbnailImageID_15107697638170.43287830172320874" width="250" height="135" style="display:inline-block;max-width:250px;max-height:250px;height:135px;width:250px;border-width:0px;vertical-align:bottom" src="https://ftsafe.com/files/upload/20161223/20161223175627585cf4cb46931.jpg"></a></div>
</td>
<td id="m_-4641350324927119200TextCell_15107697638180.40754172821668555" colspan="2" style="vertical-align:top;padding:0px;display:table-cell">
<div id="m_-4641350324927119200LPRemovePreviewContainer_15107697638180.2740388821982238"></div>
<div id="m_-4641350324927119200LPTitle_15107697638180.9837542113512676" style="color:rgb(0,106,77);font-weight:normal;font-size:21px;font-family:wf_segoe-ui_light,"Segoe UI Light","Segoe WP Light","Segoe UI","Segoe WP",Tahoma,Arial,sans-serif;line-height:21px">
<a id="m_-4641350324927119200LPUrlAnchor_15107697638190.5969416082188503" href="http://www.ftsafe.com/product/onlineShop" style="text-decoration:none" target="_blank">index | FEITIAN</a></div>
<div id="m_-4641350324927119200LPMetadata_15107697638190.31647761882558734" style="margin:10px 0px 16px;color:rgb(102,102,102);font-weight:normal;font-family:wf_segoe-ui_normal,"Segoe UI","Segoe WP",Tahoma,Arial,sans-serif;font-size:14px;line-height:14px">
<a href="http://www.ftsafe.com" target="_blank">www.ftsafe.com</a></div>
<div id="m_-4641350324927119200LPDescription_15107697638200.3322224662723723" style="display:block;color:rgb(102,102,102);font-weight:normal;font-family:wf_segoe-ui_normal,"Segoe UI","Segoe WP",Tahoma,Arial,sans-serif;font-size:14px;line-height:20px;max-height:100px;overflow:hidden">
A professional of security devices and solution provider includes software protection dongle,OTP,PKI ePass token, Smart Card, Smart card Reader and Mobile banking ...</div>
</td>
</tr>
</tbody>
</table>
</div>
<br>
<div></div>
</div>
</div>
</div>
<hr style="display:inline-block;width:98%">
<div id="m_-4641350324927119200divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Rob Gorrell <<a href="mailto:rwgorrel@uncg.edu" target="_blank">rwgorrel@uncg.edu</a>><br>
<b>Sent:</b> Wednesday, November 15, 2017 12:13:56 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Duo Alternatives?</font>
<div> </div>
</div><div><div class="h5">
<div>
<div dir="ltr">
<div>SafeNet Authentication Service touted a Shibboleth Agent back when we were looking... IIRC, it was less than impressive looking.<br>
</div>
<div><br>
</div>
-Rob<br>
</div>
<div class="m_-4641350324927119200x_gmail_extra"><br>
<div class="m_-4641350324927119200x_gmail_quote">On Wed, Nov 15, 2017 at 12:04 PM, Greg Haverkamp <span dir="ltr">
<<a href="mailto:gahaverkamp@lbl.gov" target="_blank">gahaverkamp@lbl.gov</a>></span> wrote:<br>
<blockquote class="m_-4641350324927119200x_gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">
<div class="m_-4641350324927119200x_gmail_extra">
<div class="m_-4641350324927119200x_gmail_quote"><span>On Wed, Nov 15, 2017 at 8:48 AM, Manuel Haim
<span dir="ltr"><<a href="mailto:haim@hrz.uni-marburg.de" target="_blank">haim@hrz.uni-marburg.de</a>></span> wrote:<br>
<blockquote class="m_-4641350324927119200x_gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Hi Josh,<br>
<br>
there seems to be a Shibboleth plugin for use with LinOTP:<br>
<a href="https://github.com/cyber-simon/idp-auth-linotp" rel="noreferrer" target="_blank">https://github.com/cyber-simon<wbr>/idp-auth-linotp</a></blockquote>
<div><br>
</div>
</span>
<div>We're using LinOTP with Shibboleth with a heavily modified (essentially unrecognizable) fork of this module.  We've been doing so for around 6 months now.</div>
<div><br>
</div>
<div>If distractions would quit getting in the way, I'd have finished at least adding U2F support and "KeyIdentity" Push Token support to the Shibboleth module.  (I'm still hoping to have a first pass of that done this week, at least for U2F; the push tokens
 are a bit trickier.)</div>
<div><br>
</div>
<div>I haven't checked InCommon Duo pricing lately; we didn't qualify, and the market price for Duo was considerably higher.  That, and we needed MFA for Active Directory desktops, and Duo's solution was ill-suited to our requirements.  However, in general,
 Duo's solution is quite a bit slicker than LinOTP's.  In particular, the LinOTP enrollment apps are sufficiently poor that we decided from the start that we had to do our own.  And, of course, the push tokens for LinOTP aren't part of the open source distro. 
 (Technically, the token code itself is there.  What's not there are the push notification servers.)</div>
<div><br>
</div>
<div>I can't currently distribute my currently module, but I don't foresee it being an issue.  I just haven't bothered doing it until I get the last two pieces in.</div>
<span>
<div> </div>
<blockquote class="m_-4641350324927119200x_gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
However, we currently plan to implement Shibboleth multi-factor<br>
authentication along with the LinOTP-fork "privacyIDEA" and Yubikey tokens.<br>
<br>
Up to now, we already have an privacyIDEA-LDAP-Proxy running for some<br>
secured applications. Instead of the password alone, the user has to<br>
enter password + Yubikey token into the password field. The LDAP-Proxy<br>
then forwards the password check to our regular LDAP servers, while the<br>
token check is forwarded to the privacyIDEA server.<br>
</blockquote>
<div><br>
</div>
</span>
<div>We have something similar for the LinOTP server.  (Not theirs, which is based on an OpenLDAP Perl backend and seemed to have concurrency issues in our testing.  We'd had one for our prior solution that we ported over.)</div>
<span class="m_-4641350324927119200x_HOEnZb"><font color="#888888">
<div><br>
</div>
<div>Greg</div>
</font></span><span>
<div> </div>
<blockquote class="m_-4641350324927119200x_gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
Kind regards,<br>
Manuel<br>
<br>
Philipps University Marburg, Germany<br>
<span><br>
<br>
<br>
Am 15.11.2017 um 17:09 schrieb O'Dowd, Josh:<br>
> I am doing due diligence for a likely Duo purchase, which I have demo’d<br>
> on campus using the outstanding Shibboleth native support.  I am curious<br>
</span>> if there are any known legitimate alternatives to Duo as a 2^nd factor<br>
<span>> solution WITHOUT sacrificing Shibboleth IdP front-channel password<br>
</span>> authentication as the 1^st factor.<br>
<span class="m_-4641350324927119200x_m_-6142433305049276458im m_-4641350324927119200x_m_-6142433305049276458HOEnZb">><br>
>  <br>
><br>
> We are not considering a custom built solution at this time.<br>
><br>
>  <br>
><br>
> I truly appreciate any feedback from the Shibboleth community.<br>
><br>
>  <br>
><br>
> Thank You!<br>
><br>
>  <br>
><br>
> Josh O’Dowd<br>
><br>
> Software Systems Engineer / Identity Access Management<br>
><br>
> University of Montana<br>
><br>
>  <br>
><br>
><br>
><br>
<br>
</span>
<div class="m_-4641350324927119200x_m_-6142433305049276458HOEnZb">
<div class="m_-4641350324927119200x_m_-6142433305049276458h5">--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">
https://wiki.shibboleth.net/co<wbr>nfluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.n<wbr>et</a><br>
</div>
</div>
</blockquote>
</span></div>
<br>
</div>
</div>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">
https://wiki.shibboleth.net/co<wbr>nfluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.n<wbr>et</a><br>
</blockquote>
</div>
<br>
<br clear="all">
<br>
-- <br>
<div class="m_-4641350324927119200x_gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr">
<div>Robert W. Gorrell<br>
IT Manager, Identity and Access Management <br>
</div>
<div>University of NC at Greensboro<br>
<span style="white-space:nowrap"><a href="tel:(336)%20334-5954" value="+13363345954" target="_blank">336-334-5954</a></span><br>
PGP Key ID B36DB0CA<br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div></div>

<br>--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div></div>