<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<meta content="text/html; charset=UTF-8">
<style type="text/css" style="">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
</style>
<div dir="ltr">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p>Thanks to both of you, that's just what I needed, works fine.</p>
<p><br>
</p>
<div id="x_Signature">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:rgb(0,0,0); font-family:Calibri,Arial,Helvetica,sans-serif,EmojiFont,"Apple Color Emoji","Segoe UI Emoji",NotoColorEmoji,"Segoe UI Symbol","Android Emoji",EmojiSymbols">
<p><span id="x_ms-rterangepaste-start"></span></p>
<div>--</div>
<div>Brandon McKean</div>
<div>IT / Systems</div>
<div>Linux Administrator</div>
<span id="x_ms-rterangepaste-end"></span><br>
<p></p>
</div>
</div>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Monday, March 19, 2018 12:17:57 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> RE: Disable Duo for ECP</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">> If you're using the MFA flow, you can check for the ECP profile in your script<br>
> and, if it's being used, force password:<br>
> <br>
> If (profileContext.getProfileId() ==<br>
> <a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__shibboleth.ent_ns_profiles_saml2_sso_ecp&d=DwICAg&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=miZFzuw8QoM26x-mnu5oWEO-IB603QUvBexO4p8siXI&s=h-oU3DjVMNwzdJmFYFxFPdvaLt2GrOqPvq7l2-5Nw10&e=">
https://urldefense.proofpoint.com/v2/url?u=http-3A__shibboleth.ent_ns_profiles_saml2_sso_ecp&d=DwICAg&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=miZFzuw8QoM26x-mnu5oWEO-IB603QUvBexO4p8siXI&s=h-oU3DjVMNwzdJmFYFxFPdvaLt2GrOqPvq7l2-5Nw10&e=</a>)<br>
<br>
Or check !profileContext.isBrowserProfile() if you want to be generic.<br>
<br>
I have Maryland's Duo Auth API code that works with ECP, I'm still digesting it and have just been too busy on the SP to deal with it.<br>
<br>
Being that AWS CLI is a pretty common use case for this, I have to wonder whether anybody is pushing them to fix that "one hour maximum" limitation on the temp credentials they issue.<br>
<br>
-- Scott<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=miZFzuw8QoM26x-mnu5oWEO-IB603QUvBexO4p8siXI&s=O7wvvHjYXqHc3VEtedZg2EldejYo8-yHavpatDj2_7Y&e=">
https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=miZFzuw8QoM26x-mnu5oWEO-IB603QUvBexO4p8siXI&s=O7wvvHjYXqHc3VEtedZg2EldejYo8-yHavpatDj2_7Y&e=</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>