<div dir="ltr"><span id="gmail-docs-internal-guid-136ba501-7fff-33e9-654c-c1af99c5afbf"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-family:Arial;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;vertical-align:baseline;white-space:pre-wrap">We are using shibboleth v3.46 with shibcas plug-in v3.3.0</span></p><br><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-family:Arial;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;vertical-align:baseline;white-space:pre-wrap">Is there a way to force an IDP initiated authentication and return a SAML response for the authentication context of refeds? In other words is there a way to configure a service provider for a specific authentication context overriding what they request upon authentication? The IdP will always return this authn context for this SP.</span></p><br><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-family:Arial;color:rgb(0,0,0);background-color:transparent;font-variant-numeric:normal;font-variant-east-asian:normal;vertical-align:baseline;white-space:pre-wrap">I have SP’s only requesting password authn context, Shibboleth passing it to CAS via the plug-in, CAS enforcing 2FA sending it Duo, and Shibboleth responding with a password authn context. The plug-in is designed to return the authn context that was requested. I don't think I can circumvent this even if there was a way to control at least the IdP initiated SAML responses.</span></p></span><div><br></div><br class="gmail-Apple-interchange-newline"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div>Scott Gilbert</div><div>IAM System Admin</div><div>ETS Enterprise Technology Services</div><div>University of California Santa Barbara</div><div><br></div></div></div></div></div></div></div></div></div>