Impersonate and RemoteAccess

Marco Naimoli marco.naimoli at unipd.it
Thu May 20 09:47:40 UTC 2021


Hello, I'm using MFA for authentication on my Shibboleth IDP installation;
it is configured to
call authn/RemoteUser and then to go on with attribute resolution. It
works, and some attributes come from authn/RemoteUser http headers (there's
a reverse proxy apache in front of the shibboleth IDP installation)
I'm trying to use the impersonate intercept and it works as expected, but
when I impersonate
another user after about 20-25 seconds the attributes using the http
headers are not created again, because those http headers are emptied.
Before 20-25 seconds there's no problem at all.
Any suggestion ?
Shibboleth IDP is a 3.4.6 installation (+jetty), apache a 2.4.x
Thank you
Marco
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210520/fde4e478/attachment.htm>


More information about the users mailing list