<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>One way is to use a host or network firewall to temporarily block
traffic to your Duo API host's IP.<br>
</p>
<div class="moz-cite-prefix">On 1/31/2020 3:00 PM, Zunan Dong wrote:<br>
</div>
<blockquote type="cite"
cite="mid:6ec51c9b-0508-20d6-3533-6037f1c04107@utoronto.ca">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<p>Thanks David, this explains it. Is there anyway that we can
test it?</p>
<p>Zunan<br>
</p>
<br>
<div class="moz-cite-prefix">On 2020-01-31 03:27 PM, IAM David
Bantz wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CAJ9XvwHRFbO7r2U5bOx-U_ZWeQ3qPiPQG=50qFmO9QmjKmO_5Q@mail.gmail.com">
<div dir="ltr">Presumably the idp.duo.failmode is triggered on
inability to connect to Duo, not on Duo receiving a request
referencing an invalid integration.</div>
<br>
<div class="gmail_quote">
<div dir="ltr" class="gmail_attr">On Fri, Jan 31, 2020 at
11:13 AM Zunan Dong <<a
href="mailto:zunan.dong@utoronto.ca"
moz-do-not-send="true">zunan.dong@utoronto.ca</a>>
wrote:<br>
</div>
<blockquote class="gmail_quote" style="margin:0px 0px 0px
0.8ex;border-left:1px solid
rgb(204,204,204);padding-left:1ex">
<div bgcolor="#FFFFFF">
<p>Hi Lee,</p>
<p>I have put idp.duo.failmode=safe along with a wrong
secretKey in duo.properties file. When I login, I pass
the primary authn(Username/Password), it shows me an
error page afterwards. I also tried to put in a wrong
apiHost, which gives me an error in the Duo iframe. I
guess this doesn't work for me.<br>
</p>
Zunan<br>
<br>
<div>On 2020-01-31 02:19 PM, Lee Foltz wrote:<br>
</div>
<blockquote type="cite">
<div dir="ltr">
<div>This is outlined here below and and example of
what we use. We are running IDP 3.4.6</div>
<div><a
href="https://wiki.shibboleth.net/confluence/pages/viewpage.action?pageId=32112643"
target="_blank" moz-do-not-send="true">https://wiki.shibboleth.net/confluence/pages/viewpage.action?pageId=32112643</a> <br>
</div>
<div><br>
</div>
<div>Configured in duo.properties</div>
<div>idp.duo.failmode = safe <br>
</div>
<div>idp.duo.failmode = secure<br>
</div>
<div><br>
</div>
<div>safe mode - In the event that Duo's service
cannot be contacted, users' authentication attempts
will be permitted if primary authentication
succeeds. (Default)</div>
<div>secure mode - In the event that Duo's service
cannot be contacted, all users' authentication
attempts will be rejected.</div>
</div>
<br>
<div class="gmail_quote">
<div dir="ltr" class="gmail_attr">On Fri, Jan 31, 2020
at 2:05 PM Zunan Dong <<a
href="mailto:zunan.dong@utoronto.ca"
target="_blank" moz-do-not-send="true">zunan.dong@utoronto.ca</a>>
wrote:<br>
</div>
<blockquote class="gmail_quote" style="margin:0px 0px
0px 0.8ex;border-left:1px solid
rgb(204,204,204);padding-left:1ex">
Hi Team,<br>
<br>
Our organization is trying to integrate Duo with
Shibboleth IdP.<br>
<br>
We're trying configuring the failmode of Duo
authentication flow. It <br>
seems like that Duo provides an optional parameter,
"duo.failmode", <br>
which should be configurable in duo.properties file.
However, I don't <br>
see any comments in duo.properties file for this
parameter. And also, <br>
there is no "failmode" field in the <br>
"net.shibboleth.idp.authn.duo.BasicDuoIntegration"
class. I'm wondering <br>
if there is a way to set the failmode of Duo
authentication? The version <br>
of our current IdP is V3.3. Any suggestion would be
helpful.<br>
<br>
Appreciated,<br>
<br>
-- <br>
Zunan Dong<br>
Authentication Systems Specialist<br>
Information Security<br>
Information Technology Services<br>
University of Toronto<br>
Email: <a href="mailto:zunan.dong@utoronto.ca"
target="_blank" moz-do-not-send="true">
zunan.dong@utoronto.ca</a><br>
<br>
-- <br>
For Consortium Member technical support, see <a
href="https://wiki.shibboleth.net/confluence/x/coFAAg"
rel="noreferrer" target="_blank"
moz-do-not-send="true">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a
href="mailto:users-unsubscribe@shibboleth.net"
target="_blank" moz-do-not-send="true">
users-unsubscribe@shibboleth.net</a><br>
</blockquote>
</div>
<br clear="all">
<div><br>
</div>
-- <br>
<div dir="ltr">
<div dir="ltr">
<div>
<div>Lee Foltz</div>
<div>Oakland University - UTS</div>
<div>Senior Identity and Access Management
Engineer</div>
<div> </div>
<div>248-370-2675</div>
</div>
</div>
</div>
<br>
<fieldset></fieldset>
<br>
</blockquote>
<br>
<pre cols="72">--
Zunan Dong
Authentication Systems Specialist
Information Security
Information Technology Services
University of Toronto
Email: <a href="mailto:zunan.dong@utoronto.ca" target="_blank" moz-do-not-send="true">zunan.dong@utoronto.ca</a>
</pre>
</div>
-- <br>
For Consortium Member technical support, see <a
href="https://wiki.shibboleth.net/confluence/x/coFAAg"
rel="noreferrer" target="_blank" moz-do-not-send="true">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a
href="mailto:users-unsubscribe@shibboleth.net"
target="_blank" moz-do-not-send="true">
users-unsubscribe@shibboleth.net</a></blockquote>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
Zunan Dong
Authentication Systems Specialist
Information Security
Information Technology Services
University of Toronto
Email: <a class="moz-txt-link-abbreviated" href="mailto:zunan.dong@utoronto.ca" moz-do-not-send="true">zunan.dong@utoronto.ca</a>
</pre>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<pre class="moz-signature" cols="72">--
%% Christopher A. Bongaarts %% <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a> %%
%% OIT - Identity Management %% <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a> %%
%% University of Minnesota %% +1 (612) 625-1809 %%
</pre>
</body>
</html>