SAML flow within MFA flow - possible c14n problem
John Watt
John.Watt at glasgow.ac.uk
Wed Sep 28 14:51:35 UTC 2022
Thanks so much Scott, this is exactly what I was looking for! We are now able to control our selection screen based on the individual flow lifetimes.
We'll look to switch this feature off when we have migrated all our users to Azure, but for now this has fixed everything.
Many thanks,
John
________________________________
From: Cantor, Scott <cantor.2 at osu.edu>
Sent: 19 September 2022 18:09
To: John Watt <John.Watt at glasgow.ac.uk>; Shib Users <users at shibboleth.net>
Subject: Re: SAML flow within MFA flow - possible c14n problem
Added a section about this to the docs since it's quite non-obvious.
In effect, you really have to set your policies in the proxy to match the policies used by the upstream IdP.
-- Scott
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220928/785d79f7/attachment.htm>
More information about the users
mailing list