Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

TitleDynamic errorURL
Description

After login at a service the service (SP) may be missing some information or requirements of the login, for example

  • To few attributes sent from the IdP
  • Required attribute valued is not sent from the IdP
  • The service requires REFEDS MFA capability of the IdP but not supported by IdP (according to IdP Metadata)
  • The IdP doesn't seem to support the forceAuthn SAML flag (either a SAML error from the errorURL or the AuthenticationInstant is not refreshed

There currently is no best-practice for how a service should inform users of non-technical shortcomings of logins. It would be convenient if IdP:s could supply URL:s to different support pages that services could referer to depending on pre-defined problems with logins. Many login problems are not detected until after login.

ACAMP at TechEx had a session regarding this. Notes and Post-ACAMP work are available at https://bit.ly/2rOYgl1

ProposerPål Axelsson
Resource requirementsA short term working-group to write up an errorURL profile with recommendations
+1'sAlbert Wu, Fredrik Domeij


TitleMake Microsoft ADFS handle REFEDS MFA Profile
Description

REFEDS MFA Profile uses the authnContextClassRef https://refeds.org/profile/mfa in the SAMLRequest to signal that MFA should be used for authentication. Microsoft ADFS cannot handle this authnContextClassRef and returns a FatalProfileException during authentication.

Diskussion notes from TechEx ACAMP session regarding REFEDS MFA in ADFS: https://bit.ly/2RTPgGb

ProposerFredrik Domeij <fredrik.domeij@umu.se>
Resource requirementsA working-group to help Microsoft add support for REFEDS MFA in ADFS, or to find a work-around to make ADFS usable in REFEDS MFA authentcation
+1'sTommy Larsson <tommy.larsson@umu.se>, Johan Peterson <johan.peterson@liu.se>, Pål Axelsson