<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body>
    <font face="Helvetica, Arial, sans-serif">Let's remove the proxying
      part of the conversation for a moment.<br>
      <br>
      Are you an InCommon Federation member?<br>
      <br>
      Thanks,<br>
      Don<br>
    </font><br>
    <div class="moz-cite-prefix">On 4/4/23 11:28 AM, Herron, Joel D
      wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:DM8PR10MB5397B83B2B850F0A39AFFB52B3939@DM8PR10MB5397.namprd10.prod.outlook.com">
      
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style>@font-face
        {font-family:Helvetica;
        panose-1:0 0 0 0 0 0 0 0 0 0;}@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;}span.EmailStyle21
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}div.WordSection1
        {page:WordSection1;}</style>
      <b><span style="font-size: 10pt; color: rgb(112, 48, 160);
          background: rgb(255, 235, 156);">CAUTION:
        </span></b><span style="font-size: 10pt; color: black;
        background: rgb(255, 235, 156);">This email originated from
        outside of JMU. Do not click links or open attachments unless
        you recognize the sender and know the content is safe.</span>
      <hr>
      <div>
        <div class="WordSection1">
          <p class="MsoNormal">Don,<o:p></o:p></p>
          <p class="MsoNormal">We are in the process of setting up okta.
            I can tell you that I have successfully proxied the IDP back
            to Okta and then you can use whatever MFA method you want to
            inside of Okta. We are still using Duo through Okta and it
            is working just fine. I will also heavily agree with Scott
             Okta’s SAML implementation is trash.<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">All I had to do was follow the proxy to
            another IDP guide and it was an easy setup.<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">Joel Herron<o:p></o:p></p>
          <p class="MsoNormal">DevOps Engineer<o:p></o:p></p>
          <p class="MsoNormal">ICIT<o:p></o:p></p>
          <p class="MsoNormal">UW-Whitewater <o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <div style="border:none;border-top:solid #B5C4DF
            1.0pt;padding:3.0pt 0in 0in 0in">
            <p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
                </span></b><span style="font-size:12.0pt;color:black">users
                <a class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.net"><users-bounces@shibboleth.net></a> on behalf of Lohr,
                Donald A - lohrda via users <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
                <b>Date: </b>Tuesday, April 4, 2023 at 10:21 AM<br>
                <b>To: </b>Cantor, Scott <a class="moz-txt-link-rfc2396E" href="mailto:cantor.2@osu.edu"><cantor.2@osu.edu></a>, Shib
                Users <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
                <b>Cc: </b>Lohr, Donald A - lohrda
                <a class="moz-txt-link-rfc2396E" href="mailto:lohrda@jmu.edu"><lohrda@jmu.edu></a><br>
                <b>Subject: </b>Re: Okta's MFA and Shibboleth<o:p></o:p></span></p>
          </div>
          <div>
            <p class="MsoNormal"><strong><span style="font-family:"Calibri",sans-serif;color:black;background:#FFE5E5">EXTERNAL
                  EMAIL</span></strong><o:p></o:p></p>
          </div>
          <p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:Helvetica">Basically my question is:
              Can a Shibboleth IdP be configured to use the Okta
              vendor's MFA product?<br>
              <br>
              Thanks,<br>
              Don</span><o:p></o:p></p>
          <div>
            <p class="MsoNormal">On 4/4/23 11:00 AM, Cantor, Scott
              wrote:<o:p></o:p></p>
          </div>
          <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
            <pre>CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.<o:p></o:p></pre>
            <pre>________________________________<o:p></o:p></pre>
            <pre><o:p> </o:p></pre>
            <pre>What may be true however is that you may not have the ability to control which applications get MFA'd by Okta, given that they very likely do not support the actual proxying semantics of SAML or have the ability to consume the RequesterID element to influence behavior.<o:p></o:p></pre>
            <pre><o:p> </o:p></pre>
            <pre>So if you didn't mean all or nothing re: MFA, then you may be correct.<o:p></o:p></pre>
            <pre><o:p> </o:p></pre>
            <pre>-- Scott<o:p></o:p></pre>
            <pre><o:p> </o:p></pre>
            <pre><o:p> </o:p></pre>
          </blockquote>
          <p class="MsoNormal"><br>
            <br>
            <o:p></o:p></p>
          <pre>-- <o:p></o:p></pre>
          <pre>D o n a l d   L o h r<o:p></o:p></pre>
          <pre>I n f o r m a t i o n   S y s t e m s<o:p></o:p></pre>
          <pre>J a m e s   M a d i s o n   U n i v e r s i t y<o:p></o:p></pre>
          <pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
        </div>
      </div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </body>
</html>