<div>On Sat, Feb 16, 2019 at 5:31 AM Tom Scavo <<a href="mailto:trscavo@gmail.com">trscavo@gmail.com</a>> wrote:<br></div><div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On Fri, Feb 15, 2019 at 7:45 PM Greg Haverkamp <<a href="mailto:gahaverkamp@lbl.gov" target="_blank">gahaverkamp@lbl.gov</a>> wrote:<br>
><br>
> at the time, we had to meet some  NIST 800-63-2 LoA 3 requirements, which we could accomplish with some tweaks to LinOTP (which Duo at the time could not meet).<br>
<br>
OTP is not resistant to verifier impersonation so by itself it does<br>
not satisfy Authenticator Assurance Level 3 (as it's now called by<br>
NIST). Duo Push is not resistant to verifier impersonation either.<br>
Just saying.</blockquote><div dir="auto"><br></div><div dir="auto">Alright.  But I didn’t say anything about 800-63-3, nor did I say anything about “by itself”.  (And, no, LoA 3 is not now called AAL3 if your requirement is specifically written as being 800-63-2.)</div><div dir="auto"><br></div><div dir="auto">It’s not terribly relevant to Shibboleth, anyway, as I had no requirement to claim Shibboleth (and all of the assertion-related stuff) at LoA 3.  But I did have other systems that required authentication at LoA 3, and Duo was insufficient. Since I’m not a Duo customer, I haven’t taken the time to figure out where Duo Push lands these days.</div><div dir="auto"><br></div><div dir="auto">Greg</div></div></div>