Skip to content

Commit c252722

Browse files
authored
Merge pull request #559 from GSA-TTS/list-phishing-resistant-options
List the phishing-resistant MFA methods we support
2 parents 04dbeb7 + 066e56d commit c252722

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

_includes/snippets/auth_content/aal_values.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ Stricter behavior can be specified by adding one of:
88
- **`http://idmanagement.gov/ns/assurance/aal/2`**
99
This is the same as the default behavior except users must authenticate with a separate second factor (i.e. not a remembered device).
1010
- **`http://idmanagement.gov/ns/assurance/aal/2?phishing_resistant=true`**
11-
This specifies that a user has been authenticated with a crytographically secure method, such as WebAuthn or using a PIV/CAC. Users must _always_ authenticate with a second factor.
11+
This specifies that a user has been authenticated with a crytographically secure method. We currently support security keys, face or touch unlock, and PIV/CAC. Users must _always_ authenticate with a second factor.
1212
- **`http://idmanagement.gov/ns/assurance/aal/2?hspd12=true`**
1313
This specifies that a user has been authenticated with an HSPD12 credential (requires PIV/CAC). Users must _always_ authenticate with a second factor.
1414
{% endcapture %}

0 commit comments

Comments
 (0)