<div dir="ltr">If a user fails authN at the IdP three times, our IdP is redirecting the browser to the SP.<div><div><br></div><div>That's generally not helpful, leaving the user on a generic SP error page.</div><div><br></div><div>Shibboleth IdP 2.4 with MCB.</div><div><br></div><div>I'm seeing the following suspicious entries in the IdP log:</div></div><div><br></div><div>
<p class=""><span class="">10:10:57.478 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:207] - submodule process login returned [false]</span></p>
<p class=""><span class="">10:10:57.478 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:312] - Current failed login count = [3]</span></p>
<p class=""><span class="">10:10:57.478 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:156] - Authentication result = [true]</span></p>
<p class=""><span class="">10:10:57.520 - INFO [Shibboleth-Access:73] - 20150403T181057Z|172.20.233.117|idp.alaska.edu:443|/profile/SAML2/Redirect/SSO|</span></p><p class="">What's going on??</p><p class="">David Bantz</p></div></div>