Thank you. We are reviewing.<div><br></div><div>Respectfully yours,</div><div>Kathy<br><br>On Monday, May 18, 2015, Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Kathy E. Wright <<a href="javascript:;" onclick="_e(event, 'cvml', 'kewrig@clemson.edu')">kewrig@clemson.edu</a>> [2015-05-17 01:01]:<br>
> I cannot duplicate our current IdP 2.4 configuration which uses<br>
> */idpAuthn/RemoteUser *with Apache ajp_proxy​ to delegate authentication to<br>
> our campus SSO portal as described here:<br>
[...]<br>
> From the browser we see the following error:<br>
> Error from identity provider:<br>
><br>
> Status: urn:oasis:names:tc:SAML:2.0:status:Requester<br>
><br>
> Sub-Status: urn:oasis:names:tc:SAML:2.0:status:AuthnFailed<br>
<br>
Look at httpd's access log (for the correct vhost that proxies to your<br>
Java servlet container) to make sure REMOTE_USER is set. The value is<br>
written to the access log by default.<br>
-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="javascript:;" onclick="_e(event, 'cvml', 'users-unsubscribe@shibboleth.net')">users-unsubscribe@shibboleth.net</a></blockquote></div><br><br>-- <br>Sent from Gmail Mobile<br>