<div dir="ltr">We're running Shibboleth IDP 4.1.5 and I'm attempting to move from the previous native Duo implementation (which involved the files conf/idp.properties, conf/authn/duo.properties, conf/authn/general-authn.xml, and conf/authn/mfa-authn-config.xml) to the Duo OIDC plugin.<br><br>I followed the documentation at <a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1374027959/DuoOIDCAuthnConfiguration">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1374027959/DuoOIDCAuthnConfiguration</a> and the only section I don't understand is 'Authentication Context Classes (i.e., Supported Principals)'. It's not clear to me what needs to be changed, where, and to what. I decided to skip it and so far several SPs that I've tested work. However, I'm running into a problem logging into the InCommon Certificate Manager webapp. The error returned by the webapp is:<br><br><blockquote style="margin:0 0 0 40px;border:none;padding:0px">Status: urn:oasis:names:tc:SAML:2.0:status:Requester<br>Sub-Status: urn:oasis:names:tc:SAML:2.0:status:NoAuthnContext<br>Message: An error occurred.</blockquote><br>And the Shib logs have:<br><br><blockquote style="margin:0 0 0 40px;border:none;padding:0px">2022-03-16 11:22:26,208 - WARN [net.shibboleth.idp.authn.impl.FinalizeAuthentication:166] - [x.y.z.a] - Profile Action FinalizeAuthentication: Authentication result for flow authn/MFA did not satisfy the request<br>2022-03-16 11:22:26,259 - WARN [org.opensaml.profile.action.impl.LogEvent:101] - [x.y.z.a] - A non-proceed event occurred while processing the request: RequestUnsupported</blockquote><br>I don't know if this is related to the 'Supported Principals' step so in duo-oidc.properties I tried changing the idp.authn.DuoOIDC.supportedPrincipals value from saml2/<a href="http://example.org/ac/classes/mfa">http://example.org/ac/classes/mfa</a>. The values I tried are:<br><br><blockquote style="margin:0 0 0 40px;border:none;padding:0px">saml2/http://<domain>/ac/classes/mfa<br>saml2/http://<fqdn of idp>/ac/classes/mfa<br>saml2/<a href="http://id.incommon.org/assurance/mfa">http://id.incommon.org/assurance/mfa</a> (I saw this referenced in general-authn.xml so I figured I'd give it a try)</blockquote><br>None of them worked, but again I'm not even sure this is related to the issue.<br><br>Any suggestions?<br><br>Thanks,<br>Jason<br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><pre cols="72">Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505<br></pre><pre cols="72"><b>VERIFY before you click!!</b>
  - Attackers make their emails look like they come from someone they don't.
  - Attackers make links look like they go to websites they don't.
  - Attackers disguise malware as receipts, invoices, faxes, etc.</pre><pre cols="72">Forward suspicious emails to <a href="mailto:phishing@swarthmore.edu" style="font-family:Arial,Helvetica,sans-serif" target="_blank">phishing@swarthmore.edu</a><span style="font-family:Arial,Helvetica,sans-serif">.</span></pre></div></div></div></div></div></div></div></div></div></div></div></div></div>