<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body>
    <font face="Helvetica, Arial, sans-serif">My question exactly and
      what would happen if you dropped DUO and went with Okta's MFA
      product for those (in this example) InCommon located minor
      applications still being protected by Shibboleth and your school
      wanted ALL applications protected via MFA (Okta's). </font><br>
    <br>
    <span style="font-family:Helvetica">Basically my question is: Can a
      Shibboleth IdP be configured to use the Okta vendor's MFA product?<br>
      <br>
      Thanks,<br>
      Don<br>
    </span><br>
    <div class="moz-cite-prefix">On 4/4/23 12:27 PM, Herron, Joel D
      wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:DM8PR10MB539744A75347A56AB4266374B3939@DM8PR10MB5397.namprd10.prod.outlook.com">
      
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]-->
      <style>@font-face
        {font-family:Helvetica;
        panose-1:0 0 0 0 0 0 0 0 0 0;}@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;}span.EmailStyle22
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}div.WordSection1
        {page:WordSection1;}</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <b><span style="font-size: 10pt; color: rgb(112, 48, 160);
          background: rgb(255, 235, 156);">CAUTION:
        </span></b><span style="font-size: 10pt; color: black;
        background: rgb(255, 235, 156);">This email originated from
        outside of JMU. Do not click links or open attachments unless
        you recognize the sender and know the content is safe.</span>
      <hr>
      <div>
        <div class="WordSection1">
          <p class="MsoNormal">We would only add the applications that
            are of university wide importance  to the portal. The
            specific departmental ones ,no we would probably not add
            those as to not clutter the portal. People already have
            those bookmarked if they use them they can continue to do it
            that way.<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <p class="MsoNormal">--Joel<o:p></o:p></p>
          <p class="MsoNormal"><o:p> </o:p></p>
          <div style="border:none;border-top:solid #B5C4DF
            1.0pt;padding:3.0pt 0in 0in 0in">
            <p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
                </span></b><span style="font-size:12.0pt;color:black">users
                <a class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.net"><users-bounces@shibboleth.net></a> on behalf of Lohr,
                Donald A - lohrda via users <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
                <b>Date: </b>Tuesday, April 4, 2023 at 11:01 AM<br>
                <b>To: </b><a class="moz-txt-link-abbreviated" href="mailto:users@shibboleth.net">users@shibboleth.net</a>
                <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
                <b>Cc: </b>Lohr, Donald A - lohrda
                <a class="moz-txt-link-rfc2396E" href="mailto:lohrda@jmu.edu"><lohrda@jmu.edu></a><br>
                <b>Subject: </b>Re: Okta's MFA and Shibboleth<o:p></o:p></span></p>
          </div>
          <div>
            <p class="MsoNormal"><strong><span style="font-family:"Calibri",sans-serif;color:black;background:#FFE5E5">EXTERNAL
                  EMAIL</span></strong><o:p></o:p></p>
          </div>
          <p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:Helvetica">Yes, I know what you mention
              about Okta and InCommon.<br>
              <br>
              For the sake of argument, let's say you were keeping
              Shibboleth/InCommon and proxying with Shibboleth.<br>
              <br>
              Will all of the applications that exist in the InCommon
              metadata have an icon in your Okta portal?<br>
              <br>
              Thanks,<br>
              Don</span><o:p></o:p></p>
          <div>
            <p class="MsoNormal">On 4/4/23 11:45 AM, Herron, Joel D
              wrote:<o:p></o:p></p>
          </div>
          <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
            <p class="MsoNormal"><b><span style="font-size:10.0pt;color:#7030A0;background:#FFEB9C">CAUTION:
                </span></b><span style="font-size:10.0pt;color:black;background:#FFEB9C">This
                email originated from outside of JMU. Do not click links
                or open attachments unless you recognize the sender and
                know the content is safe.</span>
              <o:p></o:p></p>
            <div class="MsoNormal" style="text-align:center" align="center">
              <hr width="100%" size="0" align="center">
            </div>
            <div>
              <p class="MsoNormal">Yes, we are. We will be using a third
                party integration with Okta to manage the two
                federations that we are part of. Until we implement that
                solution we will keep inCommon in shibboleth. There is
                no built-in way to manage a federation in Okta your
                either keeping shibboleth and proxying or purchasing a
                third party product to manage it for you.<o:p></o:p></p>
              <p class="MsoNormal"> <o:p></o:p></p>
              <p class="MsoNormal">--Joel<o:p></o:p></p>
              <p class="MsoNormal"> <o:p></o:p></p>
              <div style="border:none;border-top:solid #B5C4DF
                1.0pt;padding:3.0pt 0in 0in 0in">
                <p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
                    </span></b><span style="font-size:12.0pt;color:black">users <a href="mailto:users-bounces@shibboleth.net" moz-do-not-send="true">
                      <users-bounces@shibboleth.net></a> on behalf
                    of Lohr, Donald A - lohrda via users
                    <a href="mailto:users@shibboleth.net" moz-do-not-send="true"><users@shibboleth.net></a><br>
                    <b>Date: </b>Tuesday, April 4, 2023 at 10:33 AM<br>
                    <b>To: </b><a href="mailto:users@shibboleth.net" moz-do-not-send="true" class="moz-txt-link-freetext">users@shibboleth.net</a>
                    <a href="mailto:users@shibboleth.net" moz-do-not-send="true">
                      <users@shibboleth.net></a><br>
                    <b>Cc: </b>Lohr, Donald A - lohrda <a href="mailto:lohrda@jmu.edu" moz-do-not-send="true"><lohrda@jmu.edu></a><br>
                    <b>Subject: </b>Re: Okta's MFA and Shibboleth</span><o:p></o:p></p>
              </div>
              <div>
                <p class="MsoNormal"><strong><span style="font-family:"Calibri",sans-serif;color:black;background:#FFE5E5">EXTERNAL
                      EMAIL</span></strong><o:p></o:p></p>
              </div>
              <p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:Helvetica">Let's remove the
                  proxying part of the conversation for a moment.<br>
                  <br>
                  Are you an InCommon Federation member?<br>
                  <br>
                  Thanks,<br>
                  Don</span><o:p></o:p></p>
              <div>
                <p class="MsoNormal">On 4/4/23 11:28 AM, Herron, Joel D
                  wrote:<o:p></o:p></p>
              </div>
              <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                <p class="MsoNormal"><b><span style="font-size:10.0pt;color:#7030A0;background:#FFEB9C">CAUTION:
                    </span></b><span style="font-size:10.0pt;color:black;background:#FFEB9C">This
                    email originated from outside of JMU. Do not click
                    links or open attachments unless you recognize the
                    sender and know the content is safe.</span>
                  <o:p></o:p></p>
                <div class="MsoNormal" style="text-align:center" align="center">
                  <hr width="94%" size="0" align="center">
                </div>
                <div>
                  <p class="MsoNormal">Don,<o:p></o:p></p>
                  <p class="MsoNormal">We are in the process of setting
                    up okta. I can tell you that I have successfully
                    proxied the IDP back to Okta and then you can use
                    whatever MFA method you want to inside of Okta. We
                    are still using Duo through Okta and it is working
                    just fine. I will also heavily agree with Scott
                     Okta’s SAML implementation is trash.<o:p></o:p></p>
                  <p class="MsoNormal"> <o:p></o:p></p>
                  <p class="MsoNormal">All I had to do was follow the
                    proxy to another IDP guide and it was an easy setup.<o:p></o:p></p>
                  <p class="MsoNormal"> <o:p></o:p></p>
                  <p class="MsoNormal">Joel Herron<o:p></o:p></p>
                  <p class="MsoNormal">DevOps Engineer<o:p></o:p></p>
                  <p class="MsoNormal">ICIT<o:p></o:p></p>
                  <p class="MsoNormal">UW-Whitewater <o:p></o:p></p>
                  <p class="MsoNormal"> <o:p></o:p></p>
                  <p class="MsoNormal"> <o:p></o:p></p>
                  <p class="MsoNormal"> <o:p></o:p></p>
                  <div style="border:none;border-top:solid #B5C4DF
                    1.0pt;padding:3.0pt 0in 0in 0in">
                    <p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
                        </span></b><span style="font-size:12.0pt;color:black">users <a href="mailto:users-bounces@shibboleth.net" moz-do-not-send="true">
                          <users-bounces@shibboleth.net></a> on
                        behalf of Lohr, Donald A - lohrda via users
                        <a href="mailto:users@shibboleth.net" moz-do-not-send="true"><users@shibboleth.net></a><br>
                        <b>Date: </b>Tuesday, April 4, 2023 at 10:21 AM<br>
                        <b>To: </b>Cantor, Scott <a href="mailto:cantor.2@osu.edu" moz-do-not-send="true"><cantor.2@osu.edu></a>,
                        Shib Users
                        <a href="mailto:users@shibboleth.net" moz-do-not-send="true"><users@shibboleth.net></a><br>
                        <b>Cc: </b>Lohr, Donald A - lohrda <a href="mailto:lohrda@jmu.edu" moz-do-not-send="true"><lohrda@jmu.edu></a><br>
                        <b>Subject: </b>Re: Okta's MFA and Shibboleth</span><o:p></o:p></p>
                  </div>
                  <div>
                    <p class="MsoNormal"><strong><span style="font-family:"Calibri",sans-serif;color:black;background:#FFE5E5">EXTERNAL
                          EMAIL</span></strong><o:p></o:p></p>
                  </div>
                  <p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:Helvetica">Basically my
                      question is: Can a Shibboleth IdP be configured to
                      use the Okta vendor's MFA product?<br>
                      <br>
                      Thanks,<br>
                      Don</span><o:p></o:p></p>
                  <div>
                    <p class="MsoNormal">On 4/4/23 11:00 AM, Cantor,
                      Scott wrote:<o:p></o:p></p>
                  </div>
                  <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
                    <pre>CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.<o:p></o:p></pre>
                    <pre>________________________________<o:p></o:p></pre>
                    <pre> <o:p></o:p></pre>
                    <pre>What may be true however is that you may not have the ability to control which applications get MFA'd by Okta, given that they very likely do not support the actual proxying semantics of SAML or have the ability to consume the RequesterID element to influence behavior.<o:p></o:p></pre>
                    <pre> <o:p></o:p></pre>
                    <pre>So if you didn't mean all or nothing re: MFA, then you may be correct.<o:p></o:p></pre>
                    <pre> <o:p></o:p></pre>
                    <pre>-- Scott<o:p></o:p></pre>
                    <pre> <o:p></o:p></pre>
                    <pre> <o:p></o:p></pre>
                  </blockquote>
                  <p class="MsoNormal"><br>
                    <br>
                    <br>
                    <br>
                    <o:p></o:p></p>
                  <pre>-- <o:p></o:p></pre>
                  <pre>D o n a l d   L o h r<o:p></o:p></pre>
                  <pre>I n f o r m a t i o n   S y s t e m s<o:p></o:p></pre>
                  <pre>J a m e s   M a d i s o n   U n i v e r s i t y<o:p></o:p></pre>
                  <pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
                </div>
                <p class="MsoNormal"><br>
                  <br>
                  <br>
                  <o:p></o:p></p>
              </blockquote>
              <p class="MsoNormal"><br>
                <br>
                <br>
                <o:p></o:p></p>
              <pre>-- <o:p></o:p></pre>
              <pre>D o n a l d   L o h r<o:p></o:p></pre>
              <pre>I n f o r m a t i o n   S y s t e m s<o:p></o:p></pre>
              <pre>J a m e s   M a d i s o n   U n i v e r s i t y<o:p></o:p></pre>
              <pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
            </div>
            <p class="MsoNormal"><br>
              <br>
              <o:p></o:p></p>
          </blockquote>
          <p class="MsoNormal"><br>
            <br>
            <o:p></o:p></p>
          <pre>-- <o:p></o:p></pre>
          <pre>D o n a l d   L o h r<o:p></o:p></pre>
          <pre>I n f o r m a t i o n   S y s t e m s<o:p></o:p></pre>
          <pre>J a m e s   M a d i s o n   U n i v e r s i t y<o:p></o:p></pre>
          <pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
        </div>
      </div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </body>
</html>