<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p>Hi,</p>
    <p>at KU Leuven we will start using n-Auth [1] as a strong
      authentication solution within our Shibboleth IdP. n-Auth is an
      app-based solution for authentication based on public key
      cryptography which authenticates via a secure channel between the
      app and an n-Auth server (which you can host on-premise!).</p>
    <p>n-Auth can be used as a second factor, e.g. after
      username/password authentication or Kerberos.</p>
    <p>But n-Auth can also be used as the *only* factor as it combines
      already two factors (something you possess: your registered device
      & something you know: a PIN-code). Android devices with
      fingerprint support can alternatively use the fingerprint instead
      of the PIN-code.  <br>
    </p>
    <p>You can PM me if you want to see a demo.</p>
    <p>n-Auth has been developed by researchers of our crypto
      department: <a class="moz-txt-link-freetext" href="https://www.esat.kuleuven.be/cosic/">https://www.esat.kuleuven.be/cosic/</a> <br>
    </p>
    <p>We recently set up a FAQ at:
      <a class="moz-txt-link-freetext" href="https://admin.kuleuven.be/icts/services/aai/mfa/faq_en">https://admin.kuleuven.be/icts/services/aai/mfa/faq_en</a></p>
    Best regards,<br>
    <br>
    Philip Brusten<br>
    <br>
    [1] n-Auth: <a class="moz-txt-link-freetext" href="https://www.n-auth.com">https://www.n-auth.com</a><br>
    <div class="moz-cite-prefix"><br>
      On 15/11/2017 17:09, O'Dowd, Josh wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:6C4BCDAB7291C340B9D5C096C70C6C250145C83C1D@UMMAIL02.gs.umt.edu">
      <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Lucida Sans";
        panose-1:2 11 6 2 3 5 4 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal">I am doing due diligence for a likely Duo
          purchase, which I have demo’d on campus using the outstanding
          Shibboleth native support.  I am curious if there are any
          known legitimate alternatives to Duo as a 2<sup>nd</sup>
          factor solution WITHOUT sacrificing Shibboleth IdP
          front-channel password authentication as the 1<sup>st</sup>
          factor.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">We are not considering a custom built
          solution at this time.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">I truly appreciate any feedback from the
          Shibboleth community.<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal">Thank You!<o:p></o:p></p>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p class="MsoNormal"><span style="font-family:"Lucida
            Sans",sans-serif">Josh O’Dowd<o:p></o:p></span></p>
        <p class="MsoNormal"><span
            style="font-size:8.0pt;font-family:"Lucida
            Sans",sans-serif">Software Systems Engineer / Identity
            Access Management<o:p></o:p></span></p>
        <p class="MsoNormal"><span
            style="font-size:8.0pt;font-family:"Lucida
            Sans",sans-serif">University of Montana<o:p></o:p></span></p>
        <p class="MsoNormal"><o:p> </o:p></p>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
    </blockquote>
    <br>
  </body>
</html>