<html><head></head><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px"><div id="yui_3_16_0_ym19_1_1467908404550_6115">Hi, Ayelet, <br></div><div id="yui_3_16_0_ym19_1_1467908404550_6116"><br></div><div dir="ltr" id="yui_3_16_0_ym19_1_1467908404550_6117">No, I do not have experience with ECP flow itself. I can see in your case, your client may need to invoke different workflow based on the IDP error response, so you do need the error info to be included in the SAML response. Based on Scott's response, it looks like IDP code has to be changed to support this. Shibboleth supports extensions in various points of the authentication flow. It probably does not have an officially-sanctioned extension points for this, guessing from Scott's response, but I am wondering, Scott, if there is a way to override the current behavior instead of changing the code of IDP core itself -- I have done something like that myself, overriding the behavior of an internal class, accepting the risk of breaking in the next release of Shibboleth IDP. Since I am not familiar with the ECP flow myself, I cannot give you specifics of how to nor whether it is possible, but that is something you probably can look into.</div><div id="yui_3_16_0_ym19_1_1467908404550_6571" dir="ltr"><br></div><div dir="ltr">Joey<br></div><div id="yui_3_16_0_ym19_1_1467908404550_6118"><span></span></div> <div class="qtdSeparateBR"><br><br></div><div style="display: block;" class="yahoo_quoted"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir="ltr"><font face="Arial" size="2"> On Thursday, July 7, 2016 11:04 AM, ayeletgini <ayelet@hpe.com> wrote:<br></font></div> <br><br> <div class="y_msg_container">i see, thank you Scott!<br><br><br><br>--<br>View this message in context: <a href="" class="removed-link" target="_blank">http://shibboleth.1660669.n2.nabble.com/How-to-insert-detailed-message-in-saml-response-tp7626525p7626616.html</a><br>Sent from the Shibboleth - Developers mailing list archive at Nabble.com.<br>-- <br>To unsubscribe from this list send an email to <a href="" class="removed-link" ymailto="mailto:dev-unsubscribe@shibboleth.net">dev-unsubscribe@shibboleth.net</a><br><br><br></div> </div> </div> </div></div></body></html>