users unexpectedly through different Authn handler
Liam Hoekenga
liamr at umich.edu
Wed Nov 8 16:43:48 EST 2017
We're using two authn handlers based on RemoteUser - RemoteUserPlus (which
supports forceAuthn and isPassive), and RemoteUserToken (which supports
MFA).
Each of these handlers has their own set of login urls protected by various
SSO configuration options.
We've gotten some complaints that some users are being sent through our MFA
login despite not accessing MFA protected resources (which are identified
by a different authn context), nor being opted in to our MFA system.
Loooking in the logs for clues, I see this:
2017-11-08 14:26:18,573 - ERROR
[net.shibboleth.ext.spring.error.ErrorRaisingController:55] - -
Propagating exception thrown by request to
/idp/Authn/UWLoginToken;jsessionid=68F2B8913867B1AE6D2066463C81C590
Google pointed me at "IDP-889 - Handle 500 errors inside IDP".
Is there any way to tell why it's deciding to send them through that
handler?
Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171108/2e33c4cd/attachment.html>
More information about the users
mailing list