<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-NZ" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hi,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">We are upgrading shibboleth idp from v2 to v3. In v2, we implement custom login handler for levels of authentication: it composites a list of login handlers, and picks up the first possible handler according to the request authentication
 method and some custom rules, if that login handler fails, it tries the next possible login handler.  The login handler defined in handler.xml is something like:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><LoginHandler xsi:type="cust:Composite"><o:p></o:p></p>
<p class="MsoNormal">    <AuthenticationMethod>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</AuthenticationMethod><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">    <composite:LoginHandler xsi:type="cust:handler1"><o:p></o:p></p>
<p class="MsoNormal">      <AuthenticationMethod>level:0</AuthenticationMethod><o:p></o:p></p>
<p class="MsoNormal">    </composite:LoginHandler><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">    <composite:LoginHandler xsi:type="UsernamePassword" jaasConfigurationLocation="config/login.config"><o:p></o:p></p>
<p class="MsoNormal">      <AuthenticationMethod>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</AuthenticationMethod><o:p></o:p></p>
<p class="MsoNormal">      <AuthenticationMethod>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</AuthenticationMethod><o:p></o:p></p>
<p class="MsoNormal">      <AuthenticationMethod>level:0</AuthenticationMethod><o:p></o:p></p>
<p class="MsoNormal">    </composite:LoginHandler><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">    <composite:LoginHandler xsi:type="cust:handler2" jaasConfigurationLocation="config/login.config"><o:p></o:p></p>
<p class="MsoNormal">      <AuthenticationMethod>classes:Token</AuthenticationMethod><o:p></o:p></p>
<p class="MsoNormal">      <AuthenticationMethod>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</AuthenticationMethod><o:p></o:p></p>
<p class="MsoNormal">      <AuthenticationMethod>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</AuthenticationMethod><o:p></o:p></p>
<p class="MsoNormal">      <AuthenticationMethod>level:0</AuthenticationMethod><o:p></o:p></p>
<p class="MsoNormal">    </composite:LoginHandler><o:p></o:p></p>
<p class="MsoNormal">  </LoginHandler><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">In idp v3, it has feature to compose/combine login flows, not sure if it can fit our requirement. Another solution can be external authentication. Can someone give us suggestion which is the better way for our use case, external authentication
 or login flows?  Are there any documentations/examples for implementing external authentication or login flows?
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">In idp v2, it has a helper class HttpServletHelpe which provides access to internal state from servlets. Is there a compatible class in v3?
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal">Wenlai<o:p></o:p></p>
</div>
</body>
</html>