<div dir="ltr">One could front the IdP with a reverse proxy that uses mod-openidc pointing to Google and use the RemoteUser flow.</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Oct 11, 2019 at 5:48 PM Greg Haverkamp <<a href="mailto:gahaverkamp@lbl.gov" target="_blank">gahaverkamp@lbl.gov</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">There isn't (currently) a good way to do it, at least so far as I'm aware.  I go hunting every now and then.  The project that you're referencing allows you to use Google Authenticator (the app), not Google's MFA _services_.  It does it by storing OATH token secrets on its own.  (Similarly, if you're just looking for an OTP solution, we run LinOTP integrated with Shibboleth, and someone else has posted here that they use PrivacyIDEA -- a fork of LinOTP -- with Shibboleth).<div><br></div><div>I did have my deputy CIO contact me not long ago after someone posted to an EDUCAUSE list that they were doing it.  From what I could tell, they (Wake Forest) are fronting the Shibboleth IdP with the Shibboleth SP, and they've got that SP configured with Google's SAML IdP.  So, basically, they're doing external authentication using Google.  (i.e., not just MFA; they've delegated all authentication, including look-and-feel, to Google.)</div><div><br></div><div>That said, Google Cloud Platform's Identity Platform product (which is _not_ Google Cloud Identity) promises two-factor "coming soon".  Identity Platform makes available a RESTful API that can be called to perform authentication, which should allow it to be offloaded.  It would require replicating accounts to Identity Platform, and it's not yet clear what "two-factor" will mean.  I've asked my Google liaisons, who have weekly meetings with our Google reps, to ask.  I figure they might do some widget sort of thing like Auth0 or Firebase (since that's where it appears to come from) or something, but I don't know.</div><div><br></div><div>Greg</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Oct 11, 2019 at 3:36 PM IAM David Bantz <<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><font face="arial, sans-serif">Has anyone has found a good way to use Google's MFA for Google Apps with institutional SSO (IdP)?</font><div><font face="arial, sans-serif"><br></font></div><div><font face="arial, sans-serif">My mail admins tell me that Google MFA cannot be used with SSO; if so that seems a choice rather than any fundamental issue.</font></div><div><font face="arial, sans-serif"><br></font></div><div><font face="arial, sans-serif">I see a 4-year old reference to <span style="color:rgb(36,41,46)">Google authenticator authentication module for Shibboleth IdP v3 </span><a href="https://github.com/korteke/Shibboleth-IdP3-TOTP-Auth" target="_blank">https://github.com/korteke/Shibboleth-IdP3-TOTP-Auth</a> but did not see updates or indication of adoption as a strategy.</font></div><div><font face="arial, sans-serif"><br></font></div><div>(Yes, we have Duo integration with our Shibb IdP, but we're not able to license Duo for all students.)</div><div><br></div><div>David Bantz</div><div>UA OIT IAM</div></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><b>Tony Skalski</b></div><div dir="ltr">System Administrator | IT</div><div dir="ltr"><img src="https://docs.google.com/uc?export=download&id=0B8pehFb2jk1VTlJUMXNxQzlUZ0k&revid=0B8pehFb2jk1VR0ZGVzBjRksvU1NMQUdwSzNIa05Ea08ydjFFPQ" width="200" height="77"><br></div><div dir="ltr"><b>Office: </b><a href="tel:(507)786-3227" target="_blank">507-786-3227</a></div><div dir="ltr">1510 St. Olaf Avenue Northfield, MN 55057</div><div dir="ltr"><a href="http://stolaf.edu" target="_blank">stolaf.edu</a></div><div><div><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div>