eosc-kc / keycloak

Open Source Identity and Access Management For Modern Applications and Services
https://www.keycloak.org
Apache License 2.0
4 stars 4 forks source link

Add support for expressing MFA in authentication response #92

Open NicolasLiampotis opened 3 years ago

NicolasLiampotis commented 3 years ago
  1. In SAML MFA should be expressed through the AuthnContextClassRef of the authentication response
  2. In OIDC MFA can be expressed either through the acr and/or the amr claim
cgeorgilakis commented 2 years ago

Keycloak discussions for the MFA future: