<div dir="ltr">So I changed the idp.authn.DuoOIDC.supportedPrincipals value to saml2/<a href="https://refeds.org/profile/mfa">https://refeds.org/profile/mfa</a> since that's another value I saw in general-authn.xml and the docs said to consider it. Fortunately, that works. I don't understand Shib and SAML well enough to know why it works, but it works. If anyone wants to point me to where I can read up to get a better handle on it, it would be appreciated.<div><br></div><div>Jason</div><div><div><div><br></div></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Mar 16, 2022 at 11:47 AM Jason Rotunno <<a href="mailto:jrotunno@swarthmore.edu" target="_blank">jrotunno@swarthmore.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">We're running Shibboleth IDP 4.1.5 and I'm attempting to move from the previous native Duo implementation (which involved the files conf/idp.properties, conf/authn/duo.properties, conf/authn/general-authn.xml, and conf/authn/mfa-authn-config.xml) to the Duo OIDC plugin.<br><br>I followed the documentation at <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1374027959/DuoOIDCAuthnConfiguration" target="_blank">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1374027959/DuoOIDCAuthnConfiguration</a> and the only section I don't understand is 'Authentication Context Classes (i.e., Supported Principals)'. It's not clear to me what needs to be changed, where, and to what. I decided to skip it and so far several SPs that I've tested work. However, I'm running into a problem logging into the InCommon Certificate Manager webapp. The error returned by the webapp is:<br><br><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">Status: urn:oasis:names:tc:SAML:2.0:status:Requester<br>Sub-Status: urn:oasis:names:tc:SAML:2.0:status:NoAuthnContext<br>Message: An error occurred.</blockquote><br>And the Shib logs have:<br><br><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">2022-03-16 11:22:26,208 - WARN [net.shibboleth.idp.authn.impl.FinalizeAuthentication:166] - [x.y.z.a] - Profile Action FinalizeAuthentication: Authentication result for flow authn/MFA did not satisfy the request<br>2022-03-16 11:22:26,259 - WARN [org.opensaml.profile.action.impl.LogEvent:101] - [x.y.z.a] - A non-proceed event occurred while processing the request: RequestUnsupported</blockquote><br>I don't know if this is related to the 'Supported Principals' step so in duo-oidc.properties I tried changing the idp.authn.DuoOIDC.supportedPrincipals value from saml2/<a href="http://example.org/ac/classes/mfa" target="_blank">http://example.org/ac/classes/mfa</a>. The values I tried are:<br><br><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">saml2/http://<domain>/ac/classes/mfa<br>saml2/http://<fqdn of idp>/ac/classes/mfa<br>saml2/<a href="http://id.incommon.org/assurance/mfa" target="_blank">http://id.incommon.org/assurance/mfa</a> (I saw this referenced in general-authn.xml so I figured I'd give it a try)</blockquote><br>None of them worked, but again I'm not even sure this is related to the issue.<br><br>Any suggestions?<br><br>Thanks,<br>Jason<br clear="all"><div><br></div>-- <br><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><pre cols="72">Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505<br></pre><pre cols="72"><b>VERIFY before you click!!</b>
- Attackers make their emails look like they come from someone they don't.
- Attackers make links look like they go to websites they don't.
- Attackers disguise malware as receipts, invoices, faxes, etc.</pre><pre cols="72">Forward suspicious emails to <a href="mailto:phishing@swarthmore.edu" style="font-family:Arial,Helvetica,sans-serif" target="_blank">phishing@swarthmore.edu</a><span style="font-family:Arial,Helvetica,sans-serif">.</span></pre></div></div></div></div></div></div></div></div></div></div></div></div></div>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><pre cols="72">Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505<br></pre><pre cols="72"><b>VERIFY before you click!!</b>
- Attackers make their emails look like they come from someone they don't.
- Attackers make links look like they go to websites they don't.
- Attackers disguise malware as receipts, invoices, faxes, etc.</pre><pre cols="72">Forward suspicious emails to <a href="mailto:phishing@swarthmore.edu" style="font-family:Arial,Helvetica,sans-serif" target="_blank">phishing@swarthmore.edu</a><span style="font-family:Arial,Helvetica,sans-serif">.</span></pre></div></div></div></div></div></div></div></div></div></div></div></div>