How to configure step-up authentication when using an external IDP as 2nd Factor ?
Issue
Step-up authentication
is working fine when using as a 2nd condition
OTP
. In this case the access token has the ACR value
set to level 2
.
But when the 2nd condition
is external IDP, the ACR
value level remains at level 1
, although it should have been set to level 2
.
Environment
- Red Hat Single Sign-On (RH-SSO)
- 7.x
- Step-up Authentication
- Access Token ACR value
- External IDP
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.