<div dir="ltr"><div dir="ltr">Gary - <div><br></div><div> What your IDP does in that case would be dependent on your MFA configuration.</div><div><br></div><div> Unfortunately, I don't have an example to show you on how to handle the health check exception by skipping Duo, as we made the intentional decision to fail securely in our implementation. This prevents the risk of any (appropriately resourced) malicious user from mounting a DoS attack and bypassing Duo protections. Bypassable MFA is not MFA.</div><div><br></div><div> Also note, even if you are able to code up such a flow, your IDP will be aware that MFA did not complete, and -- if correctly configured -- your IDP will not be able to satisfy any login request requiring MFA (such as NIH). (And, if it does complete the authentication, it is likely misrepresenting the authentication information to the service provider, which could present liability or trust issues depending on the circumstances.)</div><div><br></div><div>Steve.</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Jul 30, 2024 at 11:00 PM Lipscomb, Gary via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="msg-7867833776800994673">
<div dir="ltr">
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
Hi list,<br>
<br>
We had an incident on the weekend after a firewall update caused access to DUO to be blocked and the Health checked failed.</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
Subsequently any sites requiring MFA failed authentication.</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
SSO password authentication was OK for non MFA protected sites.</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
22024-07-28 00:03:10,338 - 203.189.4.16 - ERROR [net.shibboleth.idp.plugin.authn.duo.impl.HealthCheckDuoOIDCAuthAPI:97] - Profile Action HealthCheckDuoOIDCAuthAPI: Duo API health check failed</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
net.shibboleth.idp.plugin.authn.duo.DuoClientException: Could not execute Duo HTTP request</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
at net.shibboleth.idp.plugin.authn.duo.nimbus.impl.NimbusClient.executeRequest(NimbusClient.java:271)</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
Caused by: java.net.SocketException: Connection reset</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
at java.base/java.net.SocketInputStream.read(SocketInputStream.java:186)</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
2024-07-28 00:03:10,339 - 203.189.4.16 - WARN [org.opensaml.profile.action.impl.LogEvent:101] - A non-proceed event occurred while processing the request: AuthenticationException<br>
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif;font-size:11pt;color:rgb(0,0,0)">
>From reading from<br>
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1374027959/DuoOIDCAuthnConfiguration#Advanced-Topics" id="m_1750010325997043798LPlnk340796" target="_blank">https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1374027959/DuoOIDCAuthnConfiguration#Advanced-Topics</a></div>
<div id="m_1750010325997043798Signature">
<p><span style="font-family:Arial,sans-serif;font-size:10pt"> </span></p>
<p><span style="font-family:Arial,sans-serif;font-size:10pt;color:rgb(0,0,0)">Before each Duo 2FA request, a back-channel lookup is made to Duo’s health check endpoint to determine if the Duo servers are accessible and accepting requests. If for some
reason they aren’t, the 2FA attempt fails but the IdP’s authentication flows resume. This is a standard part of Duo’s 2FA workflow. The benefit of this approach is, it occurs before the URL redirect in the browser, and if the Duo 2FA endpoint were not available
the IdP remains in control of the authentication process. Otherwise, the user’s browser might timeout during the 2FA request, or the user might get stuck on an error page of some kind.</span></p>
<div style="margin-top:1em;margin-bottom:1em;font-family:Arial,sans-serif;font-size:10pt;color:rgb(0,0,0)">
However, this involves an extra, frequent, back-channel network lookup and as such is subject to the same reliability/availability issues as the actual 2FA request. From investigation, it appears possible to bypass this check and still have the 2FA proceed
as normal. Consequently, from v1.3.0 onward we have included a property (<b>idp.duo.oidc.healthcheck.enabled</b>) that allows the deployer to turn off this check.</div>
<p><span style="font-family:Arial,sans-serif;font-size:10pt"><br>
</span></p>
<p><span style="font-family:Arial,sans-serif;font-size:10pt;color:rgb(0,0,0)">Should the SSO have just continued , basically bypassing MFA?</span></p>
<p><span style="font-family:Arial,sans-serif;font-size:10pt;color:rgb(0,0,0)">Is there a configuration we have missed for MFA?</span></p>
<p><span style="font-family:Arial,sans-serif;font-size:10pt;color:rgb(0,0,0)"><br>
</span></p>
<p><span style="font-family:Arial,sans-serif;font-size:10pt;color:rgb(0,0,0)">regards</span></p>
<p><span style="font-family:Arial,sans-serif;font-size:10pt;color:rgb(0,0,0)">Gary</span></p>
<p><span style="font-family:Arial,sans-serif;font-size:10pt"><br>
</span></p>
<table style="border-collapse:collapse;border-spacing:0px;box-sizing:border-box">
<tbody>
<tr>
<td style="border-bottom:1pt solid rgb(237,125,49);padding:0cm;vertical-align:top;width:13cm;height:45.95pt">
<p><span style="font-family:Arial,sans-serif;font-size:10pt;color:rgb(218,61,15)"><b>Gary Lipscomb</b></span></p>
<p><span style="font-family:Arial,sans-serif;font-size:9pt">Technical Officer, Systems</span></p>
<p><span style="font-family:Arial,sans-serif;font-size:9pt">IT </span><span style="font-family:Arial,sans-serif;font-size:9pt;color:rgb(65,65,65)">Infrastructure & Security | Division of Information Technology</span></p>
</td>
</tr>
<tr>
<td style="padding:0cm;vertical-align:top;width:13cm;height:65.65pt">
<p><span style="font-family:Arial,sans-serif;font-size:10pt"><br>
Charles Sturt University, Bathurst, NSW 2795</span></p>
<p><span style="font-family:Arial,sans-serif;font-size:10pt">Ph: 02 6338 6533</span></p>
<p><span style="font-family:Arial,sans-serif;font-size:10pt">Email: </span><span style="font-family:Arial,sans-serif;font-size:10pt;color:red"><a href="mailto:glipscomb@csu.edu.au" style="margin-top:0px;margin-bottom:0px" target="_blank">glipscomb@csu.edu.au</a></span><span style="font-family:Arial,sans-serif;font-size:10pt"> </span></p>
<p><span style="font-family:Arial,sans-serif;font-size:10pt;color:rgb(218,61,15)"><a href="http://www.csu.edu.au/" style="color:rgb(218,61,15);margin-top:0px;margin-bottom:0px" target="_blank">csu.edu.au</a></span></p>
</td>
</tr>
</tbody>
</table>
<p> </p>
<p><br></p></div></div></div></blockquote></div><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div style="color:rgb(136,136,136);font-size:12.8px">Steven Premeau, Director of Enterprise Systems Architecture & Administration</div><div style="color:rgb(136,136,136);font-size:12.8px"><span style="font-size:12.8px">University of Maine System</span>: Information Technology</div><div style="color:rgb(136,136,136);font-size:12.8px">(207) 581-5836 (desk) | (207) 944-9391 (mobile)<br></div></div></div></div></div></div></div>