<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>One way is to use a host or network firewall to temporarily block
      traffic to your Duo API host's IP.<br>
    </p>
    <div class="moz-cite-prefix">On 1/31/2020 3:00 PM, Zunan Dong wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:6ec51c9b-0508-20d6-3533-6037f1c04107@utoronto.ca">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <p>Thanks David, this explains it. Is there anyway that we can
        test it?</p>
      <p>Zunan<br>
      </p>
      <br>
      <div class="moz-cite-prefix">On 2020-01-31 03:27 PM, IAM David
        Bantz wrote:<br>
      </div>
      <blockquote type="cite"
cite="mid:CAJ9XvwHRFbO7r2U5bOx-U_ZWeQ3qPiPQG=50qFmO9QmjKmO_5Q@mail.gmail.com">
        <div dir="ltr">Presumably the idp.duo.failmode is triggered on
          inability to connect to Duo, not on Duo receiving a request
          referencing an invalid integration.</div>
        <br>
        <div class="gmail_quote">
          <div dir="ltr" class="gmail_attr">On Fri, Jan 31, 2020 at
            11:13 AM Zunan Dong <<a
              href="mailto:zunan.dong@utoronto.ca"
              moz-do-not-send="true">zunan.dong@utoronto.ca</a>>
            wrote:<br>
          </div>
          <blockquote class="gmail_quote" style="margin:0px 0px 0px
            0.8ex;border-left:1px solid
            rgb(204,204,204);padding-left:1ex">
            <div bgcolor="#FFFFFF">
              <p>Hi Lee,</p>
              <p>I have put idp.duo.failmode=safe along with a wrong
                secretKey in duo.properties file. When I login, I pass
                the primary authn(Username/Password), it shows me an
                error page afterwards. I also tried to put in a wrong
                apiHost, which gives me an error in the Duo iframe. I
                guess this doesn't work for me.<br>
              </p>
              Zunan<br>
              <br>
              <div>On 2020-01-31 02:19 PM, Lee Foltz wrote:<br>
              </div>
              <blockquote type="cite">
                <div dir="ltr">
                  <div>This is outlined here below and and example of
                    what we use.  We are running IDP 3.4.6</div>
                  <div><a
href="https://wiki.shibboleth.net/confluence/pages/viewpage.action?pageId=32112643"
                      target="_blank" moz-do-not-send="true">https://wiki.shibboleth.net/confluence/pages/viewpage.action?pageId=32112643</a>  <br>
                  </div>
                  <div><br>
                  </div>
                  <div>Configured in duo.properties</div>
                  <div>idp.duo.failmode = safe <br>
                  </div>
                  <div>idp.duo.failmode = secure<br>
                  </div>
                  <div><br>
                  </div>
                  <div>safe mode - In the event that Duo's service
                    cannot be contacted, users' authentication attempts
                    will be permitted if primary authentication
                    succeeds. (Default)</div>
                  <div>secure mode - In the event that Duo's service
                    cannot be contacted, all users' authentication
                    attempts will be rejected.</div>
                </div>
                <br>
                <div class="gmail_quote">
                  <div dir="ltr" class="gmail_attr">On Fri, Jan 31, 2020
                    at 2:05 PM Zunan Dong <<a
                      href="mailto:zunan.dong@utoronto.ca"
                      target="_blank" moz-do-not-send="true">zunan.dong@utoronto.ca</a>>
                    wrote:<br>
                  </div>
                  <blockquote class="gmail_quote" style="margin:0px 0px
                    0px 0.8ex;border-left:1px solid
                    rgb(204,204,204);padding-left:1ex">
                    Hi Team,<br>
                    <br>
                    Our organization is trying to integrate Duo with
                    Shibboleth IdP.<br>
                    <br>
                    We're trying configuring the failmode of Duo
                    authentication flow. It <br>
                    seems like that Duo provides an optional parameter,
                    "duo.failmode", <br>
                    which should be configurable in duo.properties file.
                    However, I don't <br>
                    see any comments in duo.properties file for this
                    parameter. And also, <br>
                    there is no "failmode" field in the <br>
                    "net.shibboleth.idp.authn.duo.BasicDuoIntegration"
                    class. I'm wondering <br>
                    if there is a way to set the failmode of Duo
                    authentication? The version <br>
                    of our current IdP is V3.3. Any suggestion would be
                    helpful.<br>
                    <br>
                    Appreciated,<br>
                    <br>
                    -- <br>
                    Zunan Dong<br>
                    Authentication Systems Specialist<br>
                    Information Security<br>
                    Information Technology Services<br>
                    University of Toronto<br>
                    Email: <a href="mailto:zunan.dong@utoronto.ca"
                      target="_blank" moz-do-not-send="true">
                      zunan.dong@utoronto.ca</a><br>
                    <br>
                    -- <br>
                    For Consortium Member technical support, see <a
                      href="https://wiki.shibboleth.net/confluence/x/coFAAg"
                      rel="noreferrer" target="_blank"
                      moz-do-not-send="true">
                      https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
                    To unsubscribe from this list send an email to <a
                      href="mailto:users-unsubscribe@shibboleth.net"
                      target="_blank" moz-do-not-send="true">
                      users-unsubscribe@shibboleth.net</a><br>
                  </blockquote>
                </div>
                <br clear="all">
                <div><br>
                </div>
                -- <br>
                <div dir="ltr">
                  <div dir="ltr">
                    <div>
                      <div>Lee Foltz</div>
                      <div>Oakland University - UTS</div>
                      <div>Senior Identity and Access Management
                        Engineer</div>
                      <div> </div>
                      <div>248-370-2675</div>
                    </div>
                  </div>
                </div>
                <br>
                <fieldset></fieldset>
                <br>
              </blockquote>
              <br>
              <pre cols="72">-- 
Zunan Dong
Authentication Systems Specialist
Information Security
Information Technology Services
University of Toronto
Email: <a href="mailto:zunan.dong@utoronto.ca" target="_blank" moz-do-not-send="true">zunan.dong@utoronto.ca</a>

</pre>
            </div>
            -- <br>
            For Consortium Member technical support, see <a
              href="https://wiki.shibboleth.net/confluence/x/coFAAg"
              rel="noreferrer" target="_blank" moz-do-not-send="true">
              https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
            To unsubscribe from this list send an email to <a
              href="mailto:users-unsubscribe@shibboleth.net"
              target="_blank" moz-do-not-send="true">
              users-unsubscribe@shibboleth.net</a></blockquote>
        </div>
        <br>
        <fieldset class="mimeAttachmentHeader"></fieldset>
        <br>
      </blockquote>
      <br>
      <pre class="moz-signature" cols="72">-- 
Zunan Dong
Authentication Systems Specialist
Information Security
Information Technology Services
University of Toronto
Email: <a class="moz-txt-link-abbreviated" href="mailto:zunan.dong@utoronto.ca" moz-do-not-send="true">zunan.dong@utoronto.ca</a>

</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
    </blockquote>
    <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a>          %%
%%  OIT - Identity Management  %%  <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a>  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
</pre>
  </body>
</html>