<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Can I borrow that phrase? People of the ADFS sounds like one of those prehistoric tribes, "people of the Mammoth".<br></blockquote><div> </div><div>LOL! Totally Agree!! (I won't be able to see them as the ADFS people anymore)</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">
> One question: Since the ADFS it's always answering with the attribute<br>
> ForceAuth = true in the SAML AuthRequest when we access their WS-<br>
> Federation URL resource, can we do something to prevent the ForceAuth to<br>
> appear or there's nothing that we can do (us meaning Shib's Idp) to avoid the<br>
> re-force-auth?<br>
<br>
</span>You can't do anything about the flag. The simplest solution is probably to point them at an intermediate script or something that that regenerates a new request without the flag, assuming you're not requiring signed requests, which I'm sure you're not.<br>
<div class="HOEnZb"><div class="h5"><br></div></div></blockquote><div><br></div><div>Thanks a lot, it makes sense.</div><div><br></div><div>I really appreciate your help!</div><div><br></div><div>Best,</div><div><br></div><div><br></div></div></div></div>