<div dir="ltr">Hi Steve,<div><br></div><div>Thank you for sharing how you have configured your decision process on whether the user is required to fulfill the 2FA challenge. I am going to presume that the user is still required to enter their password first?</div><div><br></div><div>Best,</div><div><br>Nadim</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Jul 6, 2021 at 9:57 AM Nate Klingenstein <<a href="mailto:ndk@sudonym.me">ndk@sudonym.me</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="auto">All neat stuff, Nadim and Steve.  Thanks for sharing.  As one of the greybeards in identity management at this point, it's exciting to see that people have found good ways to make biometrics work in practice.<div dir="auto"><br></div><div dir="auto">I'll still have my old school concerns about the inability to reset one's biometrics, but with the capabilities of modern end user devices and protocols, I think those are minimized relative to the challenges of passwords or other credentials in many deployment scenarios, as ably demonstrated in Shilen's presentation and your explanations.</div><div dir="auto"><br></div><div dir="auto">Again, thanks for passing all that along.</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Jul 6, 2021, 6:06 AM Mak, Steve <<a href="mailto:makst@upenn.edu" target="_blank">makst@upenn.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang="EN-US" style="overflow-wrap: break-word;">
<div>
<p class="MsoNormal">I wanted to add onto this discussion since it's related.<br>
<br>
For our 2FA we did something using the custom script in the MFA flow. We have a web service that knows whether a user is required to fulfill the 2FA challenge. I just built a web client inside the script that talks to a local process using http and json that
 fetches that answer.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Then we route to the 2FA flow based on the return response.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">The other route we had considered was using grouper entitlements to use an attribute to decide if a user needs to see the 2FA challenge, but we could never find a good solution regarding attribute sync delays.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">The nice thing with the script and controlling the routing internally is we can control what happens when the web service goes down.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">- Steve<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(181,196,223);padding:3pt 0in 0in">
<p class="MsoNormal"><b><span style="font-size:12pt;color:black">From: </span></b><span style="font-size:12pt;color:black">users <<a href="mailto:users-bounces@shibboleth.net" rel="noreferrer" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Nadim El-Khoury via users <<a href="mailto:users@shibboleth.net" rel="noreferrer" target="_blank">users@shibboleth.net</a>><br>
<b>Reply-To: </b>Shib Users <<a href="mailto:users@shibboleth.net" rel="noreferrer" target="_blank">users@shibboleth.net</a>><br>
<b>Date: </b>Tuesday, July 6, 2021 at 7:12 AM<br>
<b>To: </b>Nate Klingenstein <<a href="mailto:ndk@signet.id" rel="noreferrer" target="_blank">ndk@signet.id</a>><br>
<b>Cc: </b>Nadim El-Khoury <<a href="mailto:nel-khoury@springfield.edu" rel="noreferrer" target="_blank">nel-khoury@springfield.edu</a>>, "<a href="mailto:users@shibboleth.net" rel="noreferrer" target="_blank">users@shibboleth.net</a>" <<a href="mailto:users@shibboleth.net" rel="noreferrer" target="_blank">users@shibboleth.net</a>><br>
<b>Subject: </b>Re: Influence MFA authentication flow based on Username alone for phased 2FA deployment<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<div>
<p class="MsoNormal">Hi Nate,<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">If you want to see how Trusona is currently integrated with our IDP instance. <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">You can go to the link below, type Springfield College, and be redirected to our IDP. You can click on the "Sign In using Trusona." The user is taken to Trusona and presented with a QR code. The user would have already registered their
 phone. Please note that the current setup is for testing, and I am still working on modifying the login page and the flow.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><a href="https://fedsp-stage.ccp.xcal.tv/auth?continue=https://fedsp-stage.ccp.xcal.tv/parseJWT&tenant=tester&usePing=true&xoc-school-i" rel="noreferrer" target="_blank">https://fedsp-stage.ccp.xcal.tv/auth?continue=https://fedsp-stage.ccp.xcal.tv/parseJWT&tenant=tester&usePing=true&xoc-school-i</a><u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Best,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Nadim<u></u><u></u></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal">On Sun, Jul 4, 2021 at 9:32 AM Nadim El-Khoury <<a href="mailto:nel-khoury@springfield.edu" rel="noreferrer" target="_blank">nel-khoury@springfield.edu</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border-top:none;border-right:none;border-bottom:none;border-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<div>
<p class="MsoNormal"><span style="color:black">Hi Nate,</span><u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black">I am not sure how many are aware of it; Duke University developed its own internal Password-less solution called Duke Unlock.</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><a href="https://meetings.internet2.edu/media/medialibrary/2019/12/05/20191210-patel-webauthn.pdf" rel="noreferrer" target="_blank">https://meetings.internet2.edu/media/medialibrary/2019/12/05/20191210-patel-webauthn.pdf</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><a href="https://www.incommon.org/news/duke-unlock-one-step-multi-factor/" rel="noreferrer" target="_blank">https://www.incommon.org/news/duke-unlock-one-step-multi-factor/</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black"><a href="https://oit.duke.edu/what-we-do/applications/duke-unlock" rel="noreferrer" target="_blank">https://oit.duke.edu/what-we-do/applications/duke-unlock</a></span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="color:black">Best,</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black">Nadim El-Khoury</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black">Director of Networks, Systems, Infrastructure, and Information Security Officer</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black">Springfield College</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black">263 Alden Street</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black">Springfield, MA 01109</span><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black">email: <a href="mailto:nel-khoury@springfield.edu" rel="noreferrer" target="_blank">nel-khoury@springfield.edu</a></span><u></u><u></u></p>
</div>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal">On Sun, Jul 4, 2021 at 8:50 AM Nadim El-Khoury <<a href="mailto:nel-khoury@springfield.edu" rel="noreferrer" target="_blank">nel-khoury@springfield.edu</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border-top:none;border-right:none;border-bottom:none;border-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<div>
<p class="MsoNormal">Hi Nate,<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Thank you for the detailed information and steps. I will post back once I get the flow working. <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">We are going to use <a href="https://www.trusona.com/why-trusona/passwordless-mfa" rel="noreferrer" target="_blank">
Trusona</a> 2FA passwordless solution. In the beginning, they did not provide any integration with Shibboleth, but after talking to other universities and us, they added Shibboleth as one of their supported applications. You might want to look at their solution. <u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<div>
<p class="MsoNormal">Best,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Nadim El-Khoury<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Director of Networks, Systems, Infrastructure, and Information Security Officer<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Springfield College<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">263 Alden Street<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Springfield, MA 01109<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">email: <a href="mailto:nel-khoury@springfield.edu" rel="noreferrer" target="_blank">nel-khoury@springfield.edu</a><u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal">On Fri, Jul 2, 2021 at 9:18 PM Nate Klingenstein <<a href="mailto:ndk@signet.id" rel="noreferrer" target="_blank">ndk@signet.id</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border-top:none;border-right:none;border-bottom:none;border-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal" style="margin-bottom:12pt">Nadim,<br>
<br>
I believe you could set up a flow that does that by presenting a page for username entry, then using a JavaScript comparison against a derived principal(or even the username as entered) in your MFA script as a conditional means to pick which flow to proceed
 to.  Part of the conditional flow example in the Wiki could help, but development of the complete set of flows and scripting will be a meaningful amount of work.<br>
<br>
<a href="https://wiki.shibboleth.net/confluence/display/IDP4/MultiFactorAuthnConfiguration" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/display/IDP4/MultiFactorAuthnConfiguration</a><br>
<br>
However, I'm also curious how the 2FA/MFA solution works.  Usually, I hear 2FA defined as serial presentation of a combination of "something you know" and "something you have" and "something you intrinsically are", and MFA as simultaneous presentation of those. 
 It doesn't sound like "something you know" is a part of this, so I wonder what the two factors look like, given some of the challenges "something you intrinsically are" can present.<br>
<br>
<a href="https://en.wikipedia.org/wiki/Multi-factor_authentication" rel="noreferrer" target="_blank">https://en.wikipedia.org/wiki/Multi-factor_authentication</a><br>
<br>
Take care,<br>
Nate.<br>
<br>
--------<br>
Signet, Inc.<br>
The Art of Access ®<br>
<br>
<a href="https://www.signet.id" rel="noreferrer" target="_blank">https://www.signet.id</a><br>
<br>
-----Original message-----<br>
From: Nadim El-Khoury via users<br>
Sent: Saturday, July 3 2021, 1:00 am<br>
To: <a href="mailto:users@shibboleth.net" rel="noreferrer" target="_blank">users@shibboleth.net</a><br>
Cc: Nadim El-Khoury<br>
Subject: Influence MFA authentication flow based on Username alone for phased 2FA deployment<br>
<br>
Hi Everyone,<br>
<br>
Is there a way to influence MFA authentication flow based on the Username alone?<br>
<br>
We want to phase the deployment of 2FA based on whether the user is part of phase1, phase2, and so forth. Our 2FA is passwordless and does not require the user to enter their username and password.<br>
<br>
So, we want only to display the Username field on the Login page. The user enters their username, and we determine whether to display the password field or send them to our 2FA passwordless SAML setup.<br>
<br>
I read most of the threads about MFA and went over the documentation, and there was one topic where the MFA flow was modified based on relying party.<br>
<br>
Best,<br>
<br>
Nadim El-Khoury<br>
<br>
Director of Networks, Systems, Infrastructure, and Information Security Officer<br>
<br>
Springfield College<br>
<br>
263 Alden Street<br>
<br>
Springfield, MA 01109<br>
<br>
email: <a href="mailto:nel-khoury@springfield.edu" rel="noreferrer" target="_blank">nel-khoury@springfield.edu</a> <mailto:<a href="mailto:nel-khoury@springfield.edu" rel="noreferrer" target="_blank">nel-khoury@springfield.edu</a>><br>
<br>
--<br>
<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" rel="noreferrer" target="_blank">
users-unsubscribe@shibboleth.net</a><br>
<br>
<u></u><u></u></p>
</blockquote>
</div>
</blockquote>
</div>
</blockquote>
</div>
</div>
</div>
</div>

-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" rel="noreferrer" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>