- This line was added.
- This line was removed.
- Formatting was changed.
In the above diagram the authentication flow for SFO is shown.
- The service (SP, like ADFS, Citrix, F5 or any other capable system) performs the 1st authentication factor itself, outside of SURFsecureID. This is usually done directly against the IDP of the institution.
- The user's credentials (usually username/password) are validated by the IDP and the result of the 1st authentication factor is sent back tot he service.
- The service then starts the 2nd factor authentication by sending the user to the SURFsecureID Authentication gateway (SA-GW) using a SAML authnrequest. There, the user selects his 2nd factor token type and the 2nd factor authentication is started.
- The user's 2nd factor token is validated.
- The result is sent back to the SA-GW.
- If the 2nd factor authentication was successful, the user is sent back to the service with a SAML response indicating the result of the process. The user is now successfully authenticated at the service.