Skip to Content.
Sympa Menu

mfa-interop - Re: [MFA-Interop] Software support for our MFA Interoperability authnContext value

Subject: MFA Interop Working Group

List archive

Re: [MFA-Interop] Software support for our MFA Interoperability authnContext value


Chronological Thread 
  • From: Nicholas Roy <>
  • To: <>
  • Subject: Re: [MFA-Interop] Software support for our MFA Interoperability authnContext value
  • Date: Fri, 7 Oct 2016 14:01:27 -0600
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:mY103xRtc4lZaxciPErjVabPq9psv+yvbD5Q0YIujvd0So/mwa67bBSN2/xhgRfzUJnB7Loc0qyN7PCmBDdLuMvJmUtBWaIPfidNsd8RkQ0kDZzNImzAB9muURYHGt9fXkRu5XCxPBsdMs//Y1rPvi/6tmZKSV3JHFEqfaGtRsaS0pz2hKiO/MiHZgtBwTu7fb5oKw2erAPascwTho0kLbw+nEjnuHxNLsJXzmNvIVuI1yz794/k+oRk4gxRve4s7chNTf+8cqglG+8LRA86Onw4sZW4/SLIShGCsyZEXw==
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

A quick Google search uncovered this:

https://simplesamlphp.org/docs/1.14/saml:authproc_expectedauthncontextclassref

But the other authproc filter that page mentions, which should allow the SP to request an authncontextclass does not seem to exist in the docs:

https://simplesamlphp.org/docs/1.14/simplesamlphp-authproc

Seems like this is something that SSP should support if it doesn't, and I don't think that missing it should block adoption of this profile. The profile should drive software that doesn't support it, to support it.

Nick


On 10/7/16 1:07 PM, David Walker wrote:

Everyone,

The REFEDS Assurance Work Group that is reviewing our MFA interoperability profile has asked if we know what SAML implementations would support it. I have said that Shibboleth does; do any of you know about SimpleSAMLphp or other SAML implementations (IdP or SP)?

David






Archive powered by MHonArc 2.6.19.

Top of Page