<div dir="ltr"><span id="m_7646692658657973506m_8458079158113434726gmail-docs-internal-guid-befb7075-7fff-abdc-8918-4854a947bd1b"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-family:Arial;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;vertical-align:baseline;white-space:pre-wrap">Shib IdP 3.4.6</span></p><br><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-family:Arial;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;vertical-align:baseline;white-space:pre-wrap">I have made the necessary config changes re REFEDS MFA to the idp.properties and general-authn.xml files outlined on the shibcas plug-in page.</span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-family:Arial;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;vertical-align:baseline;white-space:pre-wrap"><a href="https://github.com/Unicon/shib-cas-authn3" target="_blank">https://github.com/Unicon/shib-cas-authn3</a></span></p><br><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-family:Arial;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;vertical-align:baseline;white-space:pre-wrap">Duo is working ok but it doesn't look like I am getting MFA validation in the idp-process.log. Not sure why the shibcas plug-in instructions say to state PasswordProtectedTransport other than thats the default.</span></p><br><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-family:Arial;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;vertical-align:baseline;white-space:pre-wrap">2020-02-18 11:08:38,777 -  - INFO [net.unicon.idp.externalauth.CasDuoSecurityRefedsAuthnMethodTranslator:91] - Overriding the principal authn context class ref to urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</span></p><br><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-family:Arial;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;vertical-align:baseline;white-space:pre-wrap">2020-02-18 11:08:38,777 -  - INFO [net.unicon.idp.externalauth.CasDuoSecurityRefedsAuthnMethodTranslator:122] - The final requested authn context class ref principals are [AuthnContextClassRefPrincipal{authnContextClassRef=urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport}]</span></p><br><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-family:Arial;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;vertical-align:baseline;white-space:pre-wrap">I know the shibcas plug-in is probably outside the realm of this list but is there a way to get some validation that authn is passwordprotected or mfa. Is there a bean I can add to relying party maybe get something back in the SAML? Or perhaps add another class ref to the general-authn.xml file? </span></p></span><br><div><div dir="ltr" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><br></div><div>Scott Gilbert</div><div>IAM System Admin</div><div>ETS Enterprise Technology Services</div><div>University of California Santa Barbara</div><div><br></div></div></div></div></div></div></div></div></div>