<div dir="ltr">Hi,Nate<div><br></div><div>Thanks for your quick reply!!</div></div><div class="gmail_extra"><br><div class="gmail_quote">2018-10-04 20:22 GMT+09:00 Nate Klingenstein <span dir="ltr"><<a href="mailto:ndk@sudonym.me" target="_blank">ndk@sudonym.me</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Noriyuki,<div><br></div><div>Sure, it's totally possible.  You just need to have each authentication mechanism configured and enabled(Password and whatever External configuration you need to do for the OpenID Connect provider) and added to the IdP's MFA map.  Then, build the right logic for transitions in your IdP's mfa-authn-config.xml file.  Make certain that the canonicalized subject names resulting from both steps match.</div><div><br></div><div>Take care,</div><div>Nate.</div></div><div class="gmail_extra"><br><div class="gmail_quote"><div><div class="h5">On Thu, Oct 4, 2018 at 2:14 AM, Noriyuki TAKEI <span dir="ltr"><<a href="mailto:ntakei@sios.com" target="_blank">ntakei@sios.com</a>></span> wrote:<br></div></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div><div class="h5"><div dir="ltr"><div dir="ltr">Hi,all<div><br></div><div>Is it possible to use ExternalAuthnConfiguration in MultiFactorAuthnConfigurati<wbr>on?</div><div><br></div><div>I'd like to log in to specific SP with flow as below.</div><div><br></div><div>1.At first,a user authenticates using ldap</div><div><br></div><div>2.Next, a user is redirected to OpenID Connect Provider and authenticates.</div><div><br></div><div>3.If authentication succeeds,a user can access to SP.</div></div></div>
<br></div></div><span class="HOEnZb"><font color="#888888">-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/co<wbr>nfluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br></font></span></blockquote></div><br></div>
<br>-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr">・‥…━━━━━━━━━━━━━━━━━━━━━━━…‥<br> サイオステクノロジー株式会社<br>  技術部<br>  クラウドソリューショングループ<br>  武井 宜行<br>  〒106-0047  東京都港区南麻布二丁目 12 番 3 号 サイオスビル<br>  TEL:070-6569-1211 (直通) 03-6401-5117 (部代表)<br>  URL:<a href="http://www.sios.com/" target="_blank">http://www.sios.com/</a><br><br> ■SIOSの最新情報はこちらから!「いいね!」をお待ちしています■<br> (SIOS Technology):<a href="http://www.facebook.com/SIOSTechnology" target="_blank">http://www.facebook.com/SIOSTechnology</a><br> (OSSよろず相談室):<a href="http://www.facebook.com/OSSyorozu" target="_blank">http://www.facebook.com/OSSyorozu</a><br><br> ■Twitter公式アカウント■<br> <a href="https://twitter.com/#!/SIOS_Technology" target="_blank">https://twitter.com/#!/SIOS_Technology</a><br>・‥…━━━━━━━━━━━━━━━━━━━━━━━…‥</div></div></div></div></div></div>
</div>