Support for MFA is available with CAS 3.5.x and 3.6 via the following module: https://github.com/Unicon/cas-mfa
A variety of providers and use cases are supported including yours. Bringing that support to CAS core and 4.x is definitely on the roadmap and we are actively working on it. It will likely make its way into the core platform for either 4.2 or 4.3, possibly and preferably before the next Apereo conference. --Misagh > -----Original Message----- > From: Fredrik Jönsson [mailto:[email protected]] > Sent: Friday, November 20, 2015 5:08 AM > To: [email protected] > Subject: [cas-dev] Support for Multi-Factor Authentication? > > Hi, > > Out of curiosity, I’m wondering where CAS development currently stands > with regards to: > Support for Multi-Factor Authentication, > https://github.com/Jasig/cas/issues/572 > > We are approaching a point where we will have to implement multi factor > authentication for some services, but not for all users nor all services, > so we > need some flexible solution where services can be informed the security > level of the authentication. > > In particular, currently we are running a Shibboleth IdP which delegates > to > CAS for authentication. We primarily use CAS protocol for in house > development due to simplicity. Depending on CAS road map we may want to > consider reversing that setup to run Shibboleth as the authenticating > party in > order to make multi-factor a feasible alternative at least for systems > using > SAML 2.0 and use a CAS server delegating authentication to Shibboleth for > compatibility purposes. > > Best regards, > /Fredrik > > -- > Fredrik Jönsson, M.Sc. Email: [email protected] > System architect Phone: +46 8 790 66 03 > Kungliga tekniska högskolan (KTH) Mobile: +46 73 595 66 03 > KTH/UF/ITA > > > -- > You are currently subscribed to [email protected] as: > [email protected] To unsubscribe, change settings or access archives, > see http://www.ja-sig.org/wiki/display/JSG/cas-dev -- You are currently subscribed to [email protected] as: [email protected] To unsubscribe, change settings or access archives, see http://www.ja-sig.org/wiki/display/JSG/cas-dev
