<div dir="ltr">Noriyuki,<div><br></div><div>Sure, it's totally possible. You just need to have each authentication mechanism configured and enabled(Password and whatever External configuration you need to do for the OpenID Connect provider) and added to the IdP's MFA map. Then, build the right logic for transitions in your IdP's mfa-authn-config.xml file. Make certain that the canonicalized subject names resulting from both steps match.</div><div><br></div><div>Take care,</div><div>Nate.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Oct 4, 2018 at 2:14 AM, Noriyuki TAKEI <span dir="ltr"><<a href="mailto:ntakei@sios.com" target="_blank">ntakei@sios.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div dir="ltr">Hi,all<div><br></div><div>Is it possible to use ExternalAuthnConfiguration in <wbr>MultiFactorAuthnConfiguration?</div><div><br></div><div>I'd like to log in to specific SP with flow as below.</div><div><br></div><div>1.At first,a user authenticates using ldap</div><div><br></div><div>2.Next, a user is redirected to OpenID Connect Provider and authenticates.</div><div><br></div><div>3.If authentication succeeds,a user can access to SP.</div></div></div>
<br>-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div>