Re: enable 2fa for UAA zone
Dan Beneke
Hi CG - Thanks for the information and context. The case presented is similar in spirit to the conversation that occurred in PR #540 as noted earlier in this email by Peter. Generally, 2FA enablement is made difficult because it currently applies to all authentications broadly. We don't currently see a path for reopening this ticket and our thoughts as to why fall into two buckets: 1. It furthers the use of UAA as an identity provider and we believe it more valuable to focus on UAA as an identity proxyThere is a world where you could imagine UAA's functionality being split into two separate deployments - one acting as a proxy, the other acting as an IdP. In that world, the IdP portion could theoretically choose to maintain IdP-like features like 2FA/MFA. We aren't there yet, but with outcomes like that in mind, we want to ensure we aren't adding to the complexity of uncoupling UAA's IdP and proxy functionality sets. Regards, Dan Beneke Thanks Dan and I also followed a bit the link that Peter provided on this. |
|