<div dir="ltr">Thanks Scott,<div><br></div><div>As for why I am trying to do that custom flow, it's because:<br></div><div><p class="gmail-MsoPlainText"><br></p><p class="gmail-MsoPlainText">1) Custom business logic: The organization wants passwords not to expire
automatically after a date, but rather after that date, the user will have 3
more logins, each time they will be reminded, before the password actually
expires.</p><p class="gmail-MsoPlainText"><br></p>

<p class="gmail-MsoPlainText">2) We don't have the TOU and password expiration data in
LDAP, only in an Oracle database, so we need custom SQL calls to check/update </p><p class="gmail-MsoPlainText">2A) That the user has agreed to TOU, and which version of TOU did the user agree to, and </p><p class="gmail-MsoPlainText">2B) To check password "soft expiration" and "how many logins does this user have left before hard expiration"<br></p><p class="gmail-MsoPlainText"><span></span></p><p class="gmail-MsoPlainText"><br></p><p class="gmail-MsoPlainText">3) We cannot modify the Shib3 code itself.<br></p><p class="gmail-MsoPlainText"><br></p><p class="gmail-MsoPlainText">Unfortunately, I cannot influence this requirement in any way, even to accommodate what the technology can do, but I still need to make it happen in a very tight timeline.<br></p><p class="gmail-MsoPlainText">Thanks again! Any feedback or suggestions is really appreciated.</p><p class="gmail-MsoPlainText">Quang Luan</p></div></div>