<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<font face="Helvetica, Arial, sans-serif">Yes, I know what you
mention about Okta and InCommon.<br>
<br>
For the sake of argument, let's say you were keeping
Shibboleth/InCommon and proxying with Shibboleth.<br>
<br>
Will all of the applications that exist in the InCommon metadata
have an icon in your Okta portal?<br>
<br>
Thanks,<br>
Don<br>
</font><br>
<div class="moz-cite-prefix">On 4/4/23 11:45 AM, Herron, Joel D
wrote:<br>
</div>
<blockquote type="cite" cite="mid:DM8PR10MB5397025700AAC7FC63349393B3939@DM8PR10MB5397.namprd10.prod.outlook.com">
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]-->
<style>@font-face
{font-family:Helvetica;
panose-1:0 0 0 0 0 0 0 0 0 0;}@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";}span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;}span.EmailStyle22
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}div.WordSection1
{page:WordSection1;}</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<b><span style="font-size: 10pt; color: rgb(112, 48, 160);
background: rgb(255, 235, 156);">CAUTION:
</span></b><span style="font-size: 10pt; color: black;
background: rgb(255, 235, 156);">This email originated from
outside of JMU. Do not click links or open attachments unless
you recognize the sender and know the content is safe.</span>
<hr>
<div>
<div class="WordSection1">
<p class="MsoNormal">Yes, we are. We will be using a third
party integration with Okta to manage the two federations
that we are part of. Until we implement that solution we
will keep inCommon in shibboleth. There is no built-in way
to manage a federation in Okta your either keeping
shibboleth and proxying or purchasing a third party product
to manage it for you.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">--Joel<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div style="border:none;border-top:solid #B5C4DF
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
</span></b><span style="font-size:12.0pt;color:black">users
<a class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.net"><users-bounces@shibboleth.net></a> on behalf of Lohr,
Donald A - lohrda via users <a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
<b>Date: </b>Tuesday, April 4, 2023 at 10:33 AM<br>
<b>To: </b><a class="moz-txt-link-abbreviated" href="mailto:users@shibboleth.net">users@shibboleth.net</a>
<a class="moz-txt-link-rfc2396E" href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
<b>Cc: </b>Lohr, Donald A - lohrda
<a class="moz-txt-link-rfc2396E" href="mailto:lohrda@jmu.edu"><lohrda@jmu.edu></a><br>
<b>Subject: </b>Re: Okta's MFA and Shibboleth<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><strong><span style="font-family:"Calibri",sans-serif;color:black;background:#FFE5E5">EXTERNAL
EMAIL</span></strong><o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:Helvetica">Let's remove the proxying
part of the conversation for a moment.<br>
<br>
Are you an InCommon Federation member?<br>
<br>
Thanks,<br>
Don</span><o:p></o:p></p>
<div>
<p class="MsoNormal">On 4/4/23 11:28 AM, Herron, Joel D
wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><b><span style="font-size:10.0pt;color:#7030A0;background:#FFEB9C">CAUTION:
</span></b><span style="font-size:10.0pt;color:black;background:#FFEB9C">This
email originated from outside of JMU. Do not click links
or open attachments unless you recognize the sender and
know the content is safe.</span>
<o:p></o:p></p>
<div class="MsoNormal" style="text-align:center" align="center">
<hr width="100%" size="0" align="center">
</div>
<div>
<p class="MsoNormal">Don,<o:p></o:p></p>
<p class="MsoNormal">We are in the process of setting up
okta. I can tell you that I have successfully proxied
the IDP back to Okta and then you can use whatever MFA
method you want to inside of Okta. We are still using
Duo through Okta and it is working just fine. I will
also heavily agree with Scott Okta’s SAML
implementation is trash.<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">All I had to do was follow the proxy
to another IDP guide and it was an easy setup.<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal">Joel Herron<o:p></o:p></p>
<p class="MsoNormal">DevOps Engineer<o:p></o:p></p>
<p class="MsoNormal">ICIT<o:p></o:p></p>
<p class="MsoNormal">UW-Whitewater <o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<div style="border:none;border-top:solid #B5C4DF
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
</span></b><span style="font-size:12.0pt;color:black">users <a href="mailto:users-bounces@shibboleth.net" moz-do-not-send="true">
<users-bounces@shibboleth.net></a> on behalf
of Lohr, Donald A - lohrda via users
<a href="mailto:users@shibboleth.net" moz-do-not-send="true"><users@shibboleth.net></a><br>
<b>Date: </b>Tuesday, April 4, 2023 at 10:21 AM<br>
<b>To: </b>Cantor, Scott <a href="mailto:cantor.2@osu.edu" moz-do-not-send="true"><cantor.2@osu.edu></a>,
Shib Users
<a href="mailto:users@shibboleth.net" moz-do-not-send="true"><users@shibboleth.net></a><br>
<b>Cc: </b>Lohr, Donald A - lohrda <a href="mailto:lohrda@jmu.edu" moz-do-not-send="true"><lohrda@jmu.edu></a><br>
<b>Subject: </b>Re: Okta's MFA and Shibboleth</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><strong><span style="font-family:"Calibri",sans-serif;color:black;background:#FFE5E5">EXTERNAL
EMAIL</span></strong><o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:Helvetica">Basically my question
is: Can a Shibboleth IdP be configured to use the Okta
vendor's MFA product?<br>
<br>
Thanks,<br>
Don</span><o:p></o:p></p>
<div>
<p class="MsoNormal">On 4/4/23 11:00 AM, Cantor, Scott
wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<pre>CAUTION: This email originated from outside of JMU. Do not click links or open attachments unless you recognize the sender and know the content is safe.<o:p></o:p></pre>
<pre>________________________________<o:p></o:p></pre>
<pre> <o:p></o:p></pre>
<pre>What may be true however is that you may not have the ability to control which applications get MFA'd by Okta, given that they very likely do not support the actual proxying semantics of SAML or have the ability to consume the RequesterID element to influence behavior.<o:p></o:p></pre>
<pre> <o:p></o:p></pre>
<pre>So if you didn't mean all or nothing re: MFA, then you may be correct.<o:p></o:p></pre>
<pre> <o:p></o:p></pre>
<pre>-- Scott<o:p></o:p></pre>
<pre> <o:p></o:p></pre>
<pre> <o:p></o:p></pre>
</blockquote>
<p class="MsoNormal"><br>
<br>
<br>
<o:p></o:p></p>
<pre>-- <o:p></o:p></pre>
<pre>D o n a l d L o h r<o:p></o:p></pre>
<pre>I n f o r m a t i o n S y s t e m s<o:p></o:p></pre>
<pre>J a m e s M a d i s o n U n i v e r s i t y<o:p></o:p></pre>
<pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
</div>
<p class="MsoNormal"><br>
<br>
<o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><br>
<br>
<o:p></o:p></p>
<pre>-- <o:p></o:p></pre>
<pre>D o n a l d L o h r<o:p></o:p></pre>
<pre>I n f o r m a t i o n S y s t e m s<o:p></o:p></pre>
<pre>J a m e s M a d i s o n U n i v e r s i t y<o:p></o:p></pre>
<pre>5 4 0 . 5 6 8 . 3 7 3 0<o:p></o:p></pre>
</div>
</div>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
</body>
</html>