<meta http-equiv=Content-Type content="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--><div class=WordSection1><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Thanks for the reply Scott. <o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>The only time that MS auth method comes through is when students are coming into the Shib IdP from ADFS via the Office Mobile App. <o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Interestingly the CAS config still works with logins into O365 (I assume that O365 doesn’t require </span><a href="http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/password" target="_top" rel="nofollow" link="external"><span style='font-size:10.0pt;font-family:"Verdana",sans-serif;color:#551A8B;background:white'>http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/password</span></a> for an authentication method)<span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>. <o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Given what you have explained I will modify web.xml thus:<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal style='background:#F7F7F7'><span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'><servlet><o:p></o:p></span></p><p class=MsoNormal style='background:#F7F7F7'><span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'>    <servlet-name>UsernamePassword</servlet-name><o:p></o:p></span></p><p class=MsoNormal style='background:#F7F7F7'><span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'>    <servlet-class></span> <span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'>edu.internet2.middleware.shibboleth.idp.authn.provider.UsernamePasswordLoginServlet</servlet-class><o:p></o:p></span></p><p class=MsoNormal style='background:#F7F7F7'><span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'>    <load-on-startup>3</load-on-startup><o:p></o:p></span></p><p class=MsoNormal style='background:#F7F7F7'><span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'>    <init-param><o:p></o:p></span></p><p class=MsoNormal style='background:#F7F7F7'><span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'>        <param-name>authnMethod</param-name><o:p></o:p></span></p><p class=MsoNormal style='background:#F7F7F7'><span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'>        <param-value></span> <a href="http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/password" target="_top" rel="nofollow" link="external"><span style='font-size:10.0pt;font-family:"Verdana",sans-serif;color:#551A8B;background:white'>http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/password</span></a><span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'></param-value><o:p></o:p></span></p><p class=MsoNormal style='background:#F7F7F7'><span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'>    </init-param><o:p></o:p></span></p><p class=MsoNormal style='background:#F7F7F7'><span style='font-size:10.0pt;font-family:Consolas;color:#333333;border:none windowtext 1.0pt;padding:0in'></servlet></span><span style='font-size:10.0pt;font-family:Consolas;color:#333333'><o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Hopefully that will get me to where I need to be.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'>Thanks again.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><br>~Seth<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><b><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'>From:</span></b><span style='font-size:11.0pt;font-family:"Calibri",sans-serif'> Cantor, Scott E. [via Shibboleth] [mailto:<a href="/user/SendEmail.jtp?type=node&node=7614501&i=0" target="_top" rel="nofollow" link="external">[hidden email]</a>] <br><b>Sent:</b> Friday, May 01, 2015 4:20 PM<br><b>To:</b> Underhill, Seth T<br><b>Subject:</b> Re: ADFS + Shib 2 Idp + CAS<o:p></o:p></span></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal style='margin-bottom:12.0pt'>On 5/1/15, 4:55 PM, "seth underhill" <<a href="/user/SendEmail.jtp?type=node&node=7614500&i=0" target="_top" rel="nofollow" link="external">[hidden email]</a>> wrote: <br><br>>Would that mean the example for ADFS V2 here: <br>> <br>><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop" target="_top" rel="nofollow" link="external">https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop</a><br>> <br>>is wrong in showing multiple <AuthenticationMethod>s in the UsernamePassword <br>>handler? <br><br>Incomplete or imperfect at least. <br><br>>I thought I would use two different types of handlers for this scenario <br>>instead of two of the same, so I tried setting the IdP to respond to the <br>>Microsoft password method in the UsernamePassword handler in my IdP instead <br>>of in RemoteUser: <br><br>That's up to you, but that means no CAS obviously. <br><br>>but I still get the same error if I go ADFS -> Shib IdP -> <br>><a href="https://myidp/idp/Authn/UserPassword" target="_top" rel="nofollow" link="external">https://myidp/idp/Authn/UserPassword</a> after <br>>the a successful auth comes back from the ldap. <br><br>That handler also returns PPT by default. Basically all of them do. <br><br>>So is it not possible for me to set the MS method in the servlet init <br>>parameter even if it is the only one for a given handler? <br><br>It's possible, but you didn't set that parameter in web.xml, at least based on the log. <br><br>-- Scott <br><br>-- <br>To unsubscribe from this list send an email to <a href="/user/SendEmail.jtp?type=node&node=7614500&i=1" target="_top" rel="nofollow" link="external">[hidden email]</a> <br><br><o:p></o:p></p><div class=MsoNormal align=center style='text-align:center'><hr size=1 width="100%" noshade style='color:#CCCCCC' align=center></div><div><div><p class=MsoNormal><b><span style='font-size:9.0pt;font-family:"Tahoma",sans-serif;color:#444444'>If you reply to this email, your message will be added to the discussion below:<o:p></o:p></span></b></p></div><p class=MsoNormal><span style='font-size:9.0pt;font-family:"Tahoma",sans-serif;color:#444444'><a href="http://shibboleth.1660669.n2.nabble.com/ADFS-Shib-2-Idp-CAS-tp7614487p7614500.html" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/ADFS-Shib-2-Idp-CAS-tp7614487p7614500.html</a> <o:p></o:p></span></p></div><div style='margin-top:4.8pt'><p class=MsoNormal style='line-height:18.0pt'><span style='font-size:8.5pt;font-family:"Tahoma",sans-serif;color:#666666'>To unsubscribe from ADFS + Shib 2 Idp + CAS, <a href="" target="_top" rel="nofollow" link="external">click here</a>.<br><a href="http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml" target="_top" rel="nofollow" link="external"><span style='font-size:7.0pt;font-family:"Times New Roman",serif'>NAML</span></a> <o:p></o:p></span></p></div></div>

        
        
        
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/ADFS-Shib-2-Idp-CAS-tp7614487p7614501.html">RE: ADFS + Shib 2 Idp + CAS</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>