On Tue, Dec 18, 2012 at 6:17 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><div class="gmail_extra"><div class="gmail_quote">
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Naresh Thota <<a href="mailto:nareshthota005@gmail.com">nareshthota005@gmail.com</a>> [2012-12-18 12:58]:<br>
<div class="im">> I am using Shibboleth IDP as My Id Provider and Configured Service Provider<br>
> by using Spring Saml Support. I am trying to authenticate the user by using<br>
> idp who is requesting a service from My Service Provider. So while<br>
> accessing the service user has prompted to enter the "User Name" &<br>
> "Password" from Service Provider Side. Then I will hold the details and<br>
> submit the request to the Shibboleth IDP. IDP is simply redirecting to<br>
> Shibboleth Login Page. I want that login page to be filled with the values<br>
> which are entered by the user initially. How can I do this.<br>
<br>
</div>Search the web for "phishing howto",<br>
-peter<br></blockquote><div><br></div><div>Seriously, we just got phished in this way (phisher cloned our IdP page and once you entered creds would POST them to the IdP. As a response we ended up modifying error.jsp to say something like, "Does this email look familiar <img src="phishMsg.png" />? If so, call IT Security".</div>
<div><br></div><div>Dave</div><div><br></div></div><div>-- <br></div>David Langenberg<div>Identity & Access Management</div><div>The University of Chicago</div><br>
</div>