<div dir="ltr">We use the shib-cas plugin to front our Shibboleth IdP deployment with CAS. Can anyone provide pointers to how we can make use of the CAS authentication attributes to define comparable attributes on the Shib side?<br><br>If you test CAS logins using /cas/login, we can see, for example, we the following set of authentication attributes:<br><br>credentialType, clientIpAddress, samlAuthenticationStatementAuthMethod, authenticationDate, bypassMultifactorAuthentication, authenticationMethod, authnContextClass, successfulAuthenticationHandlers, serverIpAddress, userAgent<br><br>In particular, we're interested in whether MFA was used for the authentication.<br><br>We've noted that the shib-cas plugin supports the REFEDS MFA profile, which suggests perhaps it's using the conditional expression (authn_method=mfa-duo && authnContextClass=mfa-duo) as the basis for its MFA assertions(?), so hopefully there's also a way to more generally define an attribute, outside of REFEDS, for the IdP to assert whether MFA was actually used in the CAS authentication?<br><br>--<br>Baron Fujimoto <<a href="mailto:baron@hawaii.edu">baron@hawaii.edu</a>> ::: UH Information Technology Services<br>minutas cantorum, minutas balorum, minutas carboratum descendus pantorum<br></div>