Duo cancel event handling. IdPv3.3/SP2.5

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Wed Jan 4 16:04:45 EST 2017


Do you guys have any recommends for how to filter/handle the 'cancel' event that comes out of a Duo user cancellation?   By default, it ultimately comes back to the SP as an AuthnFailed SAML response?  At the SP, in the /var/log/http-error.log, I am seeing an eventId parameter in the log entry:
SAML response reported an IdP error., referer: https://{ourIdPHost}/idp/profile/SAML2/Redirect/SSO?execution=e1s2&_eventId=cancel<https://%7bourIdPHost%7d/idp/profile/SAML2/Redirect/SSO?execution=e1s2&_eventId=cancel>
This ends up in the error view template on the SP.

I am wondering if there is a way to leverage the eventId at the SP so that I can have a more intuitive landing message for the user.

I also see that I can uncomment "NoPotentialFlow" in the shibboleth.LocalEventMap, and handle those at the IdP, but I am leary of how many permutations there might be there.

Ultimately we would like the 'cancel' event messaging to be friendlier than the typical authentication failed messaging.

Any advice is much appreciated.

Josh O'Dowd
Software Systems Engineer / Identity Access Management
Central IT, University of Montana


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170104/e63f89b3/attachment.html>


More information about the users mailing list