<div dir="ltr">We did experience just that, running MCB. Students persistently/repeatedly submitting bad credentials were re-directed to the SP with SAML asserting error that authN failed; to address, I changed from the default 3 tries to 99. <div class="gmail_extra"><br><div class="gmail_quote">On Wed, Jul 29, 2015 at 11:55 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> [2015-07-29 21:08]:<br>
<span class="">> Or, of course, it really was the case that user authN at the IdP was not<br>
> successful as<br>
> stated in the error: "Error from identity provider:...AuthnFailed"<br>
<br>
</span>The Shib IDP will not send you "back" (or "onwards?) to an SP with an<br>
error message, simply because you mistyped your password at the login<br>
screen, if that's what you meant. The subject would want to try again.<br>
<div class="HOEnZb"><div class="h5">-peter</div></div></blockquote></div></div></div>