Duo flow "cancel this request"
Liam Hoekenga
liamr at umich.edu
Fri Mar 29 13:06:22 EDT 2019
We're retiring our legacy SSO in favor of allowing Shibboleth to handle
it's own authentication. Currently, Cosign handles both password and Duo.
I'm playing with the Duo flow (being invoked by the MFA flow), and the
default Duo velocity template includes a link labeled "Cancel this
request". It seems to leave the user at an error page:
opensaml::FatalProfileException
...
Error from identity provider:
Status: urn:oasis:names:tc:SAML:2.0:status:Requester
Sub-Status: urn:oasis:names:tc:SAML:2.0:status:NoAuthnContext
Message: An error occurred.
Is there a more user friendly destination / message that could be displayed?
Or do most people just remove the "Cancel this request" link from the
template when they deploy Duo?
Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190329/52b382d8/attachment.html>
More information about the users
mailing list