<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<font face="Helvetica, Arial, sans-serif">Thanks, very helpful.<br>
<br>
Don<br>
</font><br>
<div class="moz-cite-prefix">On 4/4/23 4:36 PM, Peter Schober via
users wrote:<br>
</div>
<blockquote type="cite" cite="mid:ZCyKQquodgtX4h8J@aco.net">
<pre class="moz-quote-pre" wrap="">CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.
________________________________
* Lohr, Donald A - lohrda via users <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a> [2023-04-04 18:50]:
</pre>
<blockquote type="cite">
<pre class="moz-quote-pre" wrap="">I think what I am after is not being asked for correctly and thus likely not
being read correctly, because I still feel like I have unanswered questions.
</pre>
</blockquote>
<pre class="moz-quote-pre" wrap="">
No, you just keep ignoring or misreading or not understanding what
several people have been telling you here.
1. There is no integration to use Okta's MDA from your Shibboleth IDP
the way one exists for Duo. (The "API" Scott mentioned Duo having
for this but Okta not offering.)
2. The only way to still achieve Okta MDA with the Shibboleth IDP is by
activating the built-in SAML SP in the Shib IDP and integrating *that*
SAML SP with Okta (SAML proxying). Okta then only knows your
Shibboleth IDP/SP combo, it doesn't need to know anything about
federation, InCommon or R&S.
3. Anything you integrate directy with the Okta IDP you configure in
the Okta IDP, with buttons/icons and with or without MFA as desired.
4. Everything else -- including all of the less enterprisey research and
teaching tools, licensed e-journals, federation, interfederation,
InCommon, eduGAIN, etc. -- you keep on your Shib IDP as it is today.
5. People access those (item 4) protected resources same way they ever
have. When they need to log in they'll select your (Shib) IDP for
login (same as ever) and get redirected there. At that point --
instead of displaying the usual username/password field -- the Shib
IDP/SP combo will send the request along to Okta and Okta either
enforces MFA (because you want to use it for anything that comes in
"via Shibboleth") or it doesn't (because you don't want MFA for
anything coming in from your Shib IDP).
So you do have your answer:
It is possible if you give up the login screen from your Shibboleth
IDP and have it defer any and all authentication business to Okta. (If
you don't use any consent functionality in your Shib IDP this would
mean people never even see anything from your Shib IDP -- only Okta
will be seen.)
If you do not want to do this (for whatever reason) then you cannot
use Okta MFA with your Shibboleth IDP. As simple as that.
HTH,
-peter
--
For Consortium Member technical support, see <a class="moz-txt-link-freetext" href="https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!N6YHze6lT7thMl0!NCvT1tgYI8FPsQxFH9KH2_P3QlblKvrkBxF5vs_pGMSbN8hyeYAdAOAWI86IIdYDUsSzYIWQkmDwRk4T$">https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!N6YHze6lT7thMl0!NCvT1tgYI8FPsQxFH9KH2_P3QlblKvrkBxF5vs_pGMSbN8hyeYAdAOAWI86IIdYDUsSzYIWQkmDwRk4T$</a>
To unsubscribe from this list send an email to <a class="moz-txt-link-abbreviated" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a>
</pre>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>