<div dir="ltr"><div>Hi All, <br><br></div><div id="gmail-gt-res-content"><div id="gmail-gt-res-dir-ctr" dir="ltr" class="gmail-trans-verified-button-large"><div id="gmail-tts_button"></div>As it happened historically, our company uses gemalto IDProve 100 OTP tokens as 2FA for aws  login. According to the description of these tokens they can be used only with AWS. <br></div><div id="gmail-gt-res-dir-ctr" class="gmail-trans-verified-button-large">Now we would like to integrate saml 2.0 SSO, and Shibboleth  is the best candidate for this, however there a is requirement from security team to keep using uses gemalto IDProve 100 :( <br></div><div class="gmail-trans-verified-button-large">I guess main problem is that we cannot get secrets as they are known only by AWS and manufacturer. <br></div><div class="gmail-trans-verified-button-large">Is there any plugin/integration/workaround or even idea how we can use them without changing token provider to duo or yubikeys? </div><div class="gmail-trans-verified-button-large">Maybe someone already did this and can share his experience ? Any help would be much appreciated. </div><div class="gmail-trans-verified-button-large">Thank you for your help. <br></div><div class="gmail-trans-verified-button-large">BR Oleksii.<br></div><div id="gmail-gt-res-dir-ctr" class="gmail-trans-verified-button-large"><br></div></div><br></div>