Thanks Scott for the response.<div><br></div><div>That means that I have to go the ADFS and change the endopoint of the SP&#39;s app that Shib is using to send the assertion, in order to use an endpoint that&#39;s actually saml and not ws-federation, right?<br><br>Thanks,<br><br>On Thursday, January 22, 2015, Cantor, Scott &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 1/22/15, 2:27 PM, &quot;Thomas Jones&quot; &lt;<a href="javascript:;" onclick="_e(event, &#39;cvml&#39;, &#39;thomas.jones.g@gmail.com&#39;)">thomas.jones.g@gmail.com</a>&gt; wrote:<br>
<br>
<br>
&gt;<br>
&gt;I&#39;ve seen that when my external app sends the respond to Shib&#39;s Idp and<br>
&gt;this sends the respond to the ADFS, this one tries to access the next URL<br>
&gt;(but later on it sends the user back to my external app, to repeat the<br>
&gt;authentication process, as I have just<br>
&gt; mentioned):<br>
&gt;<br>
&gt;<br>
&gt;<a href="https://adfs-domain/adfs/ls/?wa=wsignin1.0&amp;wtrealm=https%3a%2f%2appcomain" target="_blank">https://adfs-domain/adfs/ls/?wa=wsignin1.0&amp;wtrealm=https%3a%2f%2appcomain</a>.<br>
&gt;com%2fapp.internet%2f&amp;wfresh=5&amp;wctx=rm%3d0%26id%3dpassive%26ru%3d%252fapp.<br>
&gt;internet%252fHome%252fStart&amp;wct=2015-01-22T00%3a15%3a24Z<br>
<br>
That&#39;s WS-Federation, not SAML. Assuming you didn&#39;t already know that.<br>
<br>
&gt;But after the user has repeated for the second time the authentication,<br>
&gt;the previous URL is not showed at all. Is this a miss configuration from<br>
&gt;the ADFS or Shib?<br>
<br>
Has nothing to do with Shibboleth.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="javascript:;" onclick="_e(event, &#39;cvml&#39;, &#39;users-unsubscribe@shibboleth.net&#39;)">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>