On Tue, Dec 18, 2012 at 6:17 AM, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br><div class="gmail_extra"><div class="gmail_quote">
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Naresh Thota &lt;<a href="mailto:nareshthota005@gmail.com">nareshthota005@gmail.com</a>&gt; [2012-12-18 12:58]:<br>
<div class="im">&gt; I am using Shibboleth IDP as My Id Provider and Configured Service Provider<br>
&gt; by using Spring Saml Support. I am trying to authenticate the user by using<br>
&gt; idp who is requesting a service from My Service Provider. So while<br>
&gt; accessing the service user has prompted to enter the &quot;User Name&quot; &amp;<br>
&gt; &quot;Password&quot; from Service Provider Side. Then I will hold the details and<br>
&gt; submit the request to the Shibboleth IDP. IDP is simply redirecting to<br>
&gt; Shibboleth Login Page. I want that login page to be filled with the values<br>
&gt; which are entered by the user initially. How can I do this.<br>
<br>
</div>Search the web for &quot;phishing howto&quot;,<br>
-peter<br></blockquote><div><br></div><div>Seriously, we just got phished in this way (phisher cloned our IdP page and once you entered creds would POST them to the IdP. As a response we ended up modifying error.jsp to say something like, &quot;Does this email look familiar &lt;img src=&quot;phishMsg.png&quot; /&gt;?  If so, call IT Security&quot;.</div>
<div><br></div><div>Dave</div><div><br></div></div><div>-- <br></div>David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div><br>
</div>