<div dir="ltr"><div>hello!<br><br>I am working through an issue where I need to release acr/amr attributes to OIDC SPs to prove specific types of MFA have occured.<br><br>We are currently releasing '<a href="https://refeds.org/profile/mfa">https://refeds.org/profile/mfa</a>' via the acr claim, which I would prefer not to mess with.</div><div><br></div><div>One option available to the OIDC SP in question is to consume the OIDC amr values passed to the SP from Shibboleth via the id_token, and use those values to determine if the SP likes what it sees. <br><br>I was trying to find a way to pass the DUO universal plugin jwt auth token amr values through to the SP. I see in 'shibboleth.oidc.DefaultIDTokenReservedClaimNames' amr is a reserved claim name, which makes sense. <br><br></div><div>I am not looking to override the <span style="background-color:transparent">DefaultIDTokenReservedClaimNames, and produce a custom resolved attribute, as that doesn't feel like the proper road to take.<br><br>Is there any 'blessed' mechanism that will allow Shibboleth to assert the amr claims returned via DUO auth_token on to the authenticating OIDC SP?<br><br>Thanks for any assistance!</span></div><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><font color="#888888">**</font><br style="color:rgb(136,136,136)"><div dir="ltr" style="color:rgb(136,136,136)"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr">Nathan Lewan<div>IT Engineer - Identity and Access Management</div><div>Division of Information Technology</div><div>University of Maryland</div></div></div></div></div></div></div></div></div></div>