NoPotentialFlow issue with a specific SP with IdP 3.2.1

Mark Cairney Mark.Cairney at ed.ac.uk
Tue Jul 5 10:29:09 EDT 2016


Ya beauty (as we would say in these parts)!
That's fixed it though it is a bit hacky.

It's quite possible that we did enable this on v2 although this specific
behaviour didn't ring any bells. Looking at my old handler.xml I do have
the "PreviousSesion" handler commented out.

This is one good reason for starting with a fairly fresh v3
configuration though is to find out which hacky bits of config are
actually required and which are just legacy cruft.

On 05/07/16 14:30, Cantor, Scott wrote:
>> Well I'm seeing different behaviour on v2 versus v3 then. I took one of
>> our v2 IdPs out the pool and cranked the logs up to DEBUG level and it's
>> doing the following:
> 
> Then you configured V2 to support forced authentication.
> 
>> So I suppose my question is how do I force Shib 3 to proceed with
>> Authentication anyway? As we use our own SSO solution with a known
>> trusted landing page RemoteUser is our only option here.
> 
> By changing the setting in the authentication configuration that describes that flow to the system in general-authn.xml
> 
> But if your SSO solution does not in fact support forced authentication, then your IdP will be lying.
> 
> -- Scott
> 

-- 
/****************************

Mark Cairney
ITI Enterprise Services
Information Services
University of Edinburgh

Tel: 0131 650 6565
Email: Mark.Cairney at ed.ac.uk
PGP: 0x435A9621

*******************************/

The University of Edinburgh is a charitable body, registered in
Scotland, with registration number SC005336.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 490 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20160705/74234c8b/attachment.sig>


More information about the users mailing list