| Table of Contents |
|---|
From the Editors
The REFEDS MFA Profile v1.1 update continues our effort to make the REFEDS MFA Profile clearer and easier to adopt. With v1.1, we focused on clarifying key implementation details and making the Profile usable with multiple messaging protocols (SAML and OIDC), while staying true to the intent of the original Profile. Along the way, we encountered issues that needed to be addressed, but fell outside the scope of this update. This document captures those issues. Where applicable, we also include recommendations for future actions.
...
Our current position is that while error handling is an important topic, this detail should be captured in a supplemental implementation guide or FAQ. For example, the following are some general scenarios:
...
SP requests REFEDS MFA, IdP understands it but is unable to perform MFA, responds with SAML Authn Assertion with something other than REFEDS MFA value (what happens?)
Earlier Working Material
The following links point to earlier discovery materials the Group compiled to organise/prioritise the Profile revision work.
Recording and Slides from the October 6 2022 REFEDS Community Chat
MFA Profile Priorities - The REFEDS MFA Subgroup recommendations to update the REFEDS MFA Profile.
...