<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body>
    <font face="Helvetica, Arial, sans-serif">Just trying to get my head
      around it all by looking at all of the possible scenarios and
      integration points (as I understand things now - with limited
      knowledge) if we were to walk down any of these paths.<br>
      <br>
      I think what I am after is not being asked for correctly and thus
      likely not being read correctly, because I still feel like I have
      unanswered questions.<br>
      <br>
      Thanks,<br>
      Don<br>
    </font><br>
    <div class="moz-cite-prefix">On 4/4/23 12:42 PM, Eric Goodman via
      users wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:SJ0PR06MB7629EDD7052200DA9C76937DFB939@SJ0PR06MB7629.namprd06.prod.outlook.com">
      
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]-->
      <style>@font-face
        {font-family:Helvetica;
        panose-1:2 11 6 4 2 2 2 2 2 4;}@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        font-size:10.0pt;
        font-family:"Courier New";}span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;}span.EmailStyle24
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}div.WordSection1
        {page:WordSection1;}</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <b><span style="font-size: 10pt; color: rgb(112, 48, 160);
          background: rgb(255, 235, 156);">CAUTION:
        </span></b><span style="font-size: 10pt; color: black;
        background: rgb(255, 235, 156);">This email originated from
        outside of JMU. Do not click links or open attachments unless
        you recognize the sender and know the content is safe.</span>
      <hr>
      <div>
        <div class="WordSection1">
          <p class="MsoNormal">No. The application asks Shibboleth to
            authenticate the user. Shibboleth hands off the
            authentication to Okta. Okta sees the application being
            “Shibboleth”. It doesn’t see the actual InCommon SP the user
            is attempting to access. You could potentially (manually)
            add applications in Okta that redirected the user to a URL
            that would initiate a login to the InCommon SP, but nothing
            would happen automatically.
            <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">If you are setting up Shibboleth to
            authenticate users of InCommon SPs against Okta via SAML,
            then you are by definition proxying. You can’t discuss the
            situation without considering the proxying aspects.
            <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">As to your other question (can Shibboleth
            use the Okta MFA product?):<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">No, not directly (at least last I
            looked). <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">Shibboleth relies on Okta MFA indirectly.
            <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">I.e., if Okta is configured to require
            MFA for the “Shibboleth” application, then every user
            authenticating to Shibboleth through Okta will be challenged
            for MFA by Okta. In this case Shibboleth logins “use” the
            Okta MFA.
            <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">However, there is no way for Shibboleth
            to explicitly request that MFA be done, to invoke the Okta
            MFA directly, or to inspect the result of the MFA challenge
            by talking to Okta. The Shibboleth operator is just relying
            on its knowledge of how Okta’s internal authentication is
            configured. (If Okta is interacting with a third party MFA
            solution, then Shibboleth could also be configured to talk
            to that, but I don’t think that’s what you are asking here).<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">--- Eric <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <div>
            <div style="border:none;border-top:solid #E1E1E1
              1.0pt;padding:3.0pt 0in 0in 0in">
              <p class="MsoNormal"><b>From:</b> users
                <a class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.net"><users-bounces@shibboleth.net></a> <b>On Behalf Of
                </b>Lohr, Donald A - lohrda via users<br>
                <b>Sent:</b> Tuesday, April 4, 2023 9:01 AM<br>
                <b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
                <b>Cc:</b> Lohr, Donald A - lohrda
                <a class="moz-txt-link-rfc2396E" href="mailto:lohrda@jmu.edu"><lohrda@jmu.edu></a><br>
                <b>Subject:</b> Re: Okta's MFA and Shibboleth<o:p></o:p></p>
            </div>
          </div>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p><strong><span style="font-size:9.0pt;font-family:"Calibri",sans-serif;color:black;background:yellow">CAUTION:
                EXTERNAL EMAIL</span></strong><o:p></o:p></p>
          <div>
            <p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Helvetica",sans-serif">Yes,
                I know what you mention about Okta and InCommon.<br>
                <br>
                For the sake of argument, let's say you were keeping
                Shibboleth/InCommon and proxying with Shibboleth.<br>
                <br>
                Will all of the applications that exist in the InCommon
                metadata have an icon in your Okta portal?<br>
                <br>
                Thanks,<br>
                Don</span><o:p></o:p></p>
            <div>
              <p class="MsoNormal">On 4/4/23 11:45 AM, Herron, Joel D
                wrote:<o:p></o:p></p>
            </div>
            <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
              <p class="MsoNormal"><b><span style="font-size:10.0pt;color:#7030A0;background:#FFEB9C">CAUTION:
                  </span></b><span style="font-size:10.0pt;color:black;background:#FFEB9C">This
                  email originated from outside of JMU. Do not click
                  links or open attachments unless you recognize the
                  sender and know the content is safe.</span>
                <o:p></o:p></p>
              <div class="MsoNormal" style="text-align:center" align="center">
                <hr width="100%" size="2" align="center">
              </div>
              <div>
                <p class="MsoNormal">Yes, we are. We will be using a
                  third party integration with Okta to manage the two
                  federations that we are part of. Until we implement
                  that solution we will keep inCommon in shibboleth.
                  There is no built-in way to manage a federation in
                  Okta your either keeping shibboleth and proxying or
                  purchasing a third party product to manage it for you.<o:p></o:p></p>
                <p class="MsoNormal"> <o:p></o:p></p>
                <p class="MsoNormal">--Joel<o:p></o:p></p>
                <p class="MsoNormal"> <o:p></o:p></p>
                <div style="border:none;border-top:solid #B5C4DF
                  1.0pt;padding:3.0pt 0in 0in 0in">
                  <p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
                      </span></b><span style="font-size:12.0pt;color:black">users <a href="mailto:users-bounces@shibboleth.net" moz-do-not-send="true">
                        <users-bounces@shibboleth.net></a> on
                      behalf of Lohr, Donald A - lohrda via users
                      <a href="mailto:users@shibboleth.net" moz-do-not-send="true"><users@shibboleth.net></a><br>
                      <b>Date: </b>Tuesday, April 4, 2023 at 10:33 AM<br>
                      <b>To: </b><a href="mailto:users@shibboleth.net" moz-do-not-send="true" class="moz-txt-link-freetext">users@shibboleth.net</a>
                      <a href="mailto:users@shibboleth.net" moz-do-not-send="true">
                        <users@shibboleth.net></a><br>
                      <b>Cc: </b>Lohr, Donald A - lohrda <a href="mailto:lohrda@jmu.edu" moz-do-not-send="true"><lohrda@jmu.edu></a><br>
                      <b>Subject: </b>Re: Okta's MFA and Shibboleth</span><o:p></o:p></p>
                </div>
                <div>
                  <p class="MsoNormal"><strong><span style="font-family:"Calibri",sans-serif;color:black;background:#FFE5E5">EXTERNAL
                        EMAIL</span></strong><o:p></o:p></p>
                </div>
                <p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Helvetica",sans-serif">Let's
                    remove the proxying part of the conversation for a
                    moment.<br>
                    <br>
                    Are you an InCommon Federation member?<br>
                    <br>
                    Thanks,<br>
                    Don</span><o:p></o:p></p>
                <div>
                  <p class="MsoNormal">On 4/4/23 11:28 AM, Herron, Joel
                    D wrote:<o:p></o:p></p>
                </div>
                <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                  <p class="MsoNormal"><b><span style="font-size:10.0pt;color:#7030A0;background:#FFEB9C">CAUTION:
                      </span></b><span style="font-size:10.0pt;color:black;background:#FFEB9C">This
                      email originated from outside of JMU. Do not click
                      links or open attachments unless you recognize the
                      sender and know the content is safe.</span>
                    <o:p></o:p></p>
                  <div class="MsoNormal" style="text-align:center" align="center">
                    <hr width="100%" size="1" align="center">
                  </div>
                  <div>
                    <p class="MsoNormal">Don,<o:p></o:p></p>
                    <p class="MsoNormal">We are in the process of
                      setting up okta. I can tell you that I have
                      successfully proxied the IDP back to Okta and then
                      you can use whatever MFA method you want to inside
                      of Okta. We are still using Duo through Okta and
                      it is working just fine. I will also heavily agree
                      with Scott  Okta’s SAML implementation is trash.<o:p></o:p></p>
                    <p class="MsoNormal"> <o:p></o:p></p>
                    <p class="MsoNormal">All I had to do was follow the
                      proxy to another IDP guide and it was an easy
                      setup.<o:p></o:p></p>
                    <p class="MsoNormal"> <o:p></o:p></p>
                    <p class="MsoNormal">Joel Herron<o:p></o:p></p>
                    <p class="MsoNormal">DevOps Engineer<o:p></o:p></p>
                    <p class="MsoNormal">ICIT<o:p></o:p></p>
                    <p class="MsoNormal">UW-Whitewater <o:p></o:p></p>
                    <p class="MsoNormal"> <o:p></o:p></p>
                    <p class="MsoNormal"> <o:p></o:p></p>
                    <p class="MsoNormal"> <o:p></o:p></p>
                    <div style="border:none;border-top:solid #B5C4DF
                      1.0pt;padding:3.0pt 0in 0in 0in">
                      <p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
                          </span></b><span style="font-size:12.0pt;color:black">users <a href="mailto:users-bounces@shibboleth.net" moz-do-not-send="true">
                            <users-bounces@shibboleth.net></a> on
                          behalf of Lohr, Donald A - lohrda via users
                          <a href="mailto:users@shibboleth.net" moz-do-not-send="true"><users@shibboleth.net></a><br>
                          <b>Date: </b>Tuesday, April 4, 2023 at 10:21
                          AM<br>
                          <b>To: </b>Cantor, Scott <a href="mailto:cantor.2@osu.edu" moz-do-not-send="true"><cantor.2@osu.edu></a>,
                          Shib Users
                          <a href="mailto:users@shibboleth.net" moz-do-not-send="true"><users@shibboleth.net></a><br>
                          <b>Cc: </b>Lohr, Donald A - lohrda <a href="mailto:lohrda@jmu.edu" moz-do-not-send="true"><lohrda@jmu.edu></a><br>
                          <b>Subject: </b>Re: Okta's MFA and Shibboleth</span><o:p></o:p></p>
                    </div>
                    <div>
                      <p class="MsoNormal"><strong><span style="font-family:"Calibri",sans-serif;color:black;background:#FFE5E5">EXTERNAL
                            EMAIL</span></strong><o:p></o:p></p>
                    </div>
                    <p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Helvetica",sans-serif">Basically my
                        question is: Can a Shibboleth IdP be configured
                        to use the Okta vendor's MFA product?<br>
                        <br>
                        Thanks,<br>
                        Don</span><o:p></o:p></p>
                    <div>
                      <p class="MsoNormal">On 4/4/23 11:00 AM, Cantor,
                        Scott wrote:<o:p></o:p></p>
                    </div>
                    <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                      <pre>CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.<o:p></o:p></pre>
                      <pre>________________________________<o:p></o:p></pre>
                      <pre> <o:p></o:p></pre>
                      <pre>What may be true however is that you may not have the ability to control which applications get MFA'd by Okta, given that they very likely do not support the actual proxying semantics of SAML or have the ability to consume the RequesterID element to influence behavior.<o:p></o:p></pre>
                      <pre> <o:p></o:p></pre>
                      <pre>So if you didn't mean all or nothing re: MFA, then you may be correct.<o:p></o:p></pre>
                      <pre> <o:p></o:p></pre>
                      <pre>-- Scott<o:p></o:p></pre>
                      <pre> <o:p></o:p></pre>
                      <pre> <o:p></o:p></pre>
                    </blockquote>
                    <p class="MsoNormal"><br>
                      <br>
                      <br>
                      <br>
                      <o:p></o:p></p>
                    <pre>-- <o:p></o:p></pre>
                    <pre>D o n a l d   L o h r<o:p></o:p></pre>
                    <pre>I n f o r m a t i o n   S y s t e m s<o:p></o:p></pre>
                    <pre>J a m e s   M a d i s o n   U n i v e r s i t y<o:p></o:p></pre>
                    <pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
                  </div>
                  <p class="MsoNormal"><br>
                    <br>
                    <br>
                    <o:p></o:p></p>
                </blockquote>
                <p class="MsoNormal"><br>
                  <br>
                  <br>
                  <o:p></o:p></p>
                <pre>-- <o:p></o:p></pre>
                <pre>D o n a l d   L o h r<o:p></o:p></pre>
                <pre>I n f o r m a t i o n   S y s t e m s<o:p></o:p></pre>
                <pre>J a m e s   M a d i s o n   U n i v e r s i t y<o:p></o:p></pre>
                <pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
              </div>
              <p class="MsoNormal"><br>
                <br>
                <o:p></o:p></p>
            </blockquote>
            <p class="MsoNormal"><br>
              <br>
              <o:p></o:p></p>
            <pre>-- <o:p></o:p></pre>
            <pre>D o n a l d   L o h r<o:p></o:p></pre>
            <pre>I n f o r m a t i o n   S y s t e m s<o:p></o:p></pre>
            <pre>J a m e s   M a d i s o n   U n i v e r s i t y<o:p></o:p></pre>
            <pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
          </div>
        </div>
      </div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </body>
</html>