<html>
  <head>
    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Hi there. <br>
    </p>
    <p>I'm currently in the process of enabling MFA for our institution
      (on IDP 4.1).<br>
    </p>
    <p>To limit the hassle on my 'angry' users, i'd like to ask for
      second factor only when the connecting IP address is not on a
      dynamic (expiring) allowlist.</p>
    <p>I already found how to use a static whitelist with
      conf/authn/mfa-authn-config.xml checkSecondFactor script. <br>
    </p>
    <p>I intend to load the address list from a database (sqlite) with
      the attribute resolver... <br>
    </p>
    <p>but where in the auth process should I write the sucessful login
      IP in the database ? <br>
    </p>
    <p><br>
    </p>
    <pre class="moz-signature" cols="72">-- 
Arnaud Houdelette
Administrateur des infrastructures systèmes et réseaux
Normandie Université</pre>
    <div id="grammalecte_menu_main_button_shadow_host" style="width:
      0px; height: 0px;"></div>
  </body>
</html>