<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p style="margin-top:0;margin-bottom:0">Hi Scott,</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0"><a href="https://refeds.org/profile/mfa" class="OWAAutoLink" id="LPlnk395174" previewremoved="true">https://refeds.org/profile/mfa</a> is an AuthnContextClassRef inserted into SAML Req/Resp. Is there any entity category
that ensures a particular IDP supports this Authn Context?<br>
<br>
</p>
<p style="margin-top:0;margin-bottom:0">I have found a final report of "Multi-Factor Authentication Inter-operability". It seems like whether to create an entity category for MFA in InCommon is still on pending. Do you have a conclusion for that?</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">Thanks,</p>
<div id="Signature">
<div id="divtagdefaultwrapper" dir="ltr" style="font-size: 12pt; color: rgb(0, 0, 0); font-family: Calibri, Helvetica, sans-serif, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols;">
<p style="margin-top:0; margin-bottom:0"><span id="ms-rterangepaste-start"></span></p>
<pre class="moz-signature" cols="72">Zunan Dong</pre>
<pre class="moz-signature" cols="72">Authentication Systems Specialist</pre>
<pre class="moz-signature" cols="72">Information Security </pre>
<pre class="moz-signature" cols="72">Information Technology Service </pre>
<pre class="moz-signature" cols="72">University of Toronto </pre>
<span id="ms-rterangepaste-end"></span><br>
<p></p>
</div>
</div>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Scott Koranda <skoranda@gmail.com><br>
<b>Sent:</b> Thursday, 25 April 2019 10:41:27 AM<br>
<b>To:</b> Shib Users<br>
<b>Cc:</b> Jin Fang<br>
<b>Subject:</b> Re: Enforce MFA for federated IDPs</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">> We have an SP requires MFA for internal users(authenticate against our
<br>
> internal IDP). Now we want users from other universities/institutions to <br>
> use this SP through federated IDPs. How do we enforce MFA for those <br>
> IDP/users? Is there a standard that helps the collaboration between SPs <br>
> and IDPs on MFA enforcement(like R&S, SIRTFI)?<br>
<br>
<a href="https://refeds.org/profile/mfa">https://refeds.org/profile/mfa</a><br>
<br>
Scott K<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>