<div dir="ltr"><div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)">Hello,<br><br></div><div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)">We are using Shibboleth IdP 2.3.6 + Kerberos Login Handler + user password login as fail-over to enable SSO for users.<br>
<br></div><div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)">For all the relying parties we have Kerberos Login Handler as the Default Login Handler (defaultAuthenticationMethod). If kerberos authentication fails the user is redirected to user password login handler. So far, all the SP have requested unsolicited (IdP initialized) SSO.<br>
<br></div><div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)">However, in some cases (where a user wants to login from another users computer) we want to bypass the (defaultAuthenticationMethod) Kerberos Login Handler and go directly to User Password page. Is there any out of box config for this ?<br>
<br></div><div class="gmail_default" style="font-family:verdana,sans-serif;color:rgb(0,0,102)">Thank you in advance for your time and help.<br clear="all"></div><br>-- <br><span style="color:rgb(0,0,102);font-family:trebuchet ms,sans-serif">Regards,</span><br style="color:rgb(0,0,102);font-family:trebuchet ms,sans-serif">
<span style="color:rgb(51,0,153);font-family:trebuchet ms,sans-serif"><span style="color:rgb(0,0,102)"> Vish</span><br style="color:rgb(0,0,102)"><br></span>
</div>