Post back result of Auth to SP after authentication fail at IDP

C G ci_98yr at yahoo.com
Mon Oct 1 10:32:32 EDT 2012


Greetings!

Have a shib-IDP with an external authentication integrated.

My requirement is: to post back the authentication result to SP (service provider)
_even when authentication fails_. What do 'need to configure or tweak so that 
after returning to AuthenticationEngine.returnToAuthenticationEngine(request, response);  
 Shib-IDP posts back the result to SP and not take back the user to login page?

Of course, will set the attribute LoginHandler.AUTHENTICATION_ERROR_KEY  to some error condition besides
setting LoginHandler.SUBJECT_KEY, LoginHandler.PRINCIPAL_KEY, [which user  failed auth].

In my case SP will decide how to handle failed auth case.

Appreciate if any one can shed some wisdom words on this. Thanks in advance.


Some details:
As per the API documentation  
validateSuccessfulAuthentication
 An authentication is considered successful if no error is bound to the request attribute LoginHandler.AUTHENTICATION_ERROR_KEY and there is a value for at least one of the following request attributes: LoginHandler.SUBJECT_KEY, LoginHandler.PRINCIPAL_KEY, or LoginHandler.PRINCIPAL_NAME_KEY. 



 [case of auth success is straightforward --thanks to
http://shibboleth.1660669.n2.nabble.com/Forwarding-authentication-request-error-404-ExternalAuth-SOLVED-td7310618.html#a7316204  ]
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121001/87ebd7df/attachment.html 


More information about the users mailing list