NoPotentialFlow issue with a specific SP with IdP 3.2.1

Cantor, Scott cantor.2 at osu.edu
Tue Jul 5 09:30:19 EDT 2016


> Well I'm seeing different behaviour on v2 versus v3 then. I took one of
> our v2 IdPs out the pool and cranked the logs up to DEBUG level and it's
> doing the following:

Then you configured V2 to support forced authentication.

> So I suppose my question is how do I force Shib 3 to proceed with
> Authentication anyway? As we use our own SSO solution with a known
> trusted landing page RemoteUser is our only option here.

By changing the setting in the authentication configuration that describes that flow to the system in general-authn.xml

But if your SSO solution does not in fact support forced authentication, then your IdP will be lying.

-- Scott



More information about the users mailing list