<div dir="ltr"><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;font-size:small"><div class="gmail_default">Hello Roberto,</div><div class="gmail_default"><br></div><div class="gmail_default">Check out this bit of documentation here: <a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1474297850/Supporting+the+REFEDS+MFA+Profile">https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1474297850/Supporting+the+REFEDS+MFA+Profile</a></div><div class="gmail_default"><br></div><div class="gmail_default">Basically what you need to do is ensure that you are directing everything to the MFA flow. Within the MFA flow, follow the example to check to see if a second factor is needed and then pass on control as needed.</div><div class="gmail_default"><br></div><div class="gmail_default">You will also need to ensure that you have the MFA principals defined and then use conf/relying-party.xml to require MFA for certain SPs.</div></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;font-size:small"><br></div><div class="gmail_default" style="font-family:arial,helvetica,sans-serif;font-size:small">Hope that helps</div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div dir="ltr"><font face="arial, helvetica, sans-serif"><br>Brian Moon<br><font size="1">Senior System Administrator, Enterprise Systems</font></font></div><div dir="ltr"><font size="1"><font face="arial, helvetica, sans-serif">Santa Clara University</font></font></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Aug 13, 2021 at 10:02 AM Wessel, Keith <<a href="mailto:kwessel@illinois.edu">kwessel@illinois.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US" style="overflow-wrap: break-word;">
<div class="gmail-m_-1375537791944571034WordSection1">
<p class="MsoNormal">That’s not true if you hve MFA configured properly. The second MFA should see that the currently satisfied authentication methods isn’t sufficient and should prompt the user for step-up authentication. That is, it’ll skip asking the user
for their username and password again but will go straight to the MFA prompt.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Keith<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(225,225,225);padding:3pt 0in 0in">
<p class="MsoNormal"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> <b>On Behalf Of
</b>Ullfig, Roberto Alfredo<br>
<b>Sent:</b> Friday, August 13, 2021 11:56 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject:</b> Forcing MFA for some SPs and not Others<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal"><span style="font-size:12pt;color:black">Is there a way for Shibboleth to create different cookies for different SPs? For instance, if I force MFA on an application on the IDP side I can easily get around MFA by logging into another SP
that doesn't require MFA first because I've already identified myself.<u></u><u></u></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:12pt;color:black"><u></u> <u></u></span></p>
</div>
<div id="gmail-m_-1375537791944571034Signature">
<div>
<div id="gmail-m_-1375537791944571034divtagdefaultwrapper">
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:10pt;font-family:Tahoma,sans-serif;color:black">---
<u></u><u></u></span></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:10pt;font-family:Arial,sans-serif;color:black">Roberto Ullfig -
<a href="mailto:rullfig@uic.edu" target="_blank">rullfig@uic.edu</a><br>
Systems Administrator<br>
Enterprise Applications & Services | Technology Solutions<br>
University of Illinois - Chicago</span><span style="font-size:10pt;font-family:Tahoma,sans-serif;color:black">
<u></u><u></u></span></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!MLMg-p0Z!WKibHMkiKehbRt_aA4QztTnM5sRY5yu43iAKRJPn2yGtdRNId64dO-3wEJMV$" rel="noreferrer" target="_blank">https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!MLMg-p0Z!WKibHMkiKehbRt_aA4QztTnM5sRY5yu43iAKRJPn2yGtdRNId64dO-3wEJMV$</a> <br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>