<div dir="ltr">Hi Michael,<br><br>Thanks for the quick reply! So, if I understand correctly, a relying party override is my only option to force MFA for Research.gov, even though they don't explicitly request it? Could you point me to any documentation or examples on how to implement this override in Shibboleth IDP?<br><br>Best,<br>Zico<br><br><br><br></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Fri, Mar 7, 2025 at 9:25 PM Michael Grady <<a href="mailto:mgrady@unicon.net">mgrady@unicon.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div><br id="m_5178420979482743805lineBreakAtBeginningOfMessage"><div><br><blockquote type="cite"><div>On Mar 7, 2025, at 9:17 AM, Zico via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> wrote:</div><br><div><br style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><span style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">I am trying to configure my Shibboleth v4 IDP for<span> </span></span><a href="http://research.gov/" style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" target="_blank">Research.gov</a><span style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inline"><span> </span>MFA. And I believe I configured everything from my side as NIH federation MFA is working fine. [ Fine means, I do see NIH enforcing "</span><a href="https://refeds.org/profile/mfa" style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" target="_blank">https://refeds.org/profile/mfa</a><span style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">" in "AuthnContextClassRef" in SAML assertion ]. </span><br style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><br style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"><span style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inline">But for<span> </span></span><a href="http://researdh.gov/" style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" target="_blank">Researdh.gov</a><span style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inline"><span> </span>I don't see anything like this. Do you have any suggestions what's wrong with my setup? I tried to contact<span> </span></span><a href="http://research.gov/" style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px" target="_blank">Research.gov</a><span style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none;float:none;display:inline"><span> </span>support but not getting enough responses. </span><br style="font-family:Helvetica;font-size:20px;font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;text-decoration:none"></div></blockquote><br></div><div>Research.gov is not setup to explicitly ask for REFEDS MFA at this time. If you don't require REFEDS MFA for everybody, then you need to configure a relying party override to indicate that REFEDS MFA is the only allowed context when an AuthnRequest comes from them. Not ideal, but that's where things stand today.</div><br><div>
<div>--<br>Michael A. Grady<br>IAM Architect, Unicon, Inc.</div><div><br></div><br>
</div>
<br></div></blockquote></div><div><br clear="all"></div><br><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature">Best,<br>Zico</div>