Is your idea to kick it back to the home IdP with requested authnContext set to only MFA
or to implement step-up MFA at the proxy?
We'd be interested in the former...
-----Original Message-----
From: Satosa-dev <satosa-dev-bounces at lists.sunet.se> On Behalf Of Scott
Koranda
Sent: Tuesday, April 23, 2019 9:07 AM
To: satosa-dev at lists.sunet.se
Subject: [Satosa-dev] SATOSA and step-up with Duo or the like
Hi,
I know it has been talked about as "doable", but has anybody already
deployed SATOSA with a response microservice that implements a "step-up"
flow to leverage a second factor (like Duo) when the authenticating IdP does
not assert that MFA was used?
If so, are you considering sharing it and/or contributing it to the code base?
If not, but you are considering such an implementation/deployment, can you
indicate if you are interested in collaborating on the development and
testing?
Thanks,
Scott K
_______________________________________________
Satosa-dev mailing list
Satosa-dev at lists.sunet.se
https://lists.sunet.se/listinfo/satosa-dev