<div dir="ltr">Thanks for the insight information, Scott.<div><br></div><div>-Terry</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Mar 16, 2023 at 2:34 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>
    
    <u></u>

<div>

<h1 style="background-color:rgb(255,255,179);font-family:arial;font-size:13px;color:rgb(255,0,0);border:1px dotted rgb(0,0,0)">CAUTION: This email originated from an external sender. Always use caution when opening links or attachments from external parties.</h1>

</div>

    > I have played a little bit and was able to get rpm based Amazon Linux working.<br>
<br>
It shouldn't require any playing, there are official packages for that and they should work like any others.<br>
<br>
> Also we plan to validate MFA when a user signs in, is it supported in Shibboleth<br>
> SP 3.2.3<br>
<br>
That entire version isn't supported, but AuthnContext processing is part of every release. It's not possible to do this in a universal way, as there are no standard ways to signal MFA (*), and the majority of commercial IdPs do not support the RequestedAuthnContext feature at all.<br>
<br>
That is an extremely "not simple" issue because of the refusal by vendors to support the standard properly and a lack of conventions around its use.<br>
<br>
It's a community/federation specific problem, basically, and there is no community when it comes to SAAS.<br>
<br>
-- Scott<br>
<br>
(*) It's also not even obvious that MFA is a thing people should want to signal any more in the future. "Strong authentication" is probably what matters, as there are methods that are better than typical MFA, but are not.<br>


    
</div>
</blockquote></div>