<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<blockquote type="cite">
<div>There should be two audit log entries for these requests, and two web access log records for a GET to the Shibboleth/SSO endpoint with the appropriate parameters.</div>
</blockquote>
<div><br>
</div>
<div>Looking in the audit log, that does appear to be the case.</div>
<div><br>
</div>
<blockquote type="cite">
<div>In which case, there's no way for the IdP to do anything about it unless the SP operator can explain why it's not happy with the first response.</div>
</blockquote>
<div><br>
</div>
<div>That makes sense, but that would make me wonder why IDPv2 had worked with it in this scenario, without any special configuration that I'm aware of.</div>
<div><br>
</div>
<div>Thanks,</div>
<div><br>
</div>
<div>Brandon McKean</div>
<div><br>
</div>
<div>On Tue, 2015-08-04 at 17:13 +0000, Cantor, Scott wrote:</div>
<blockquote type="cite">
<pre>On 8/4/15, 1:08 PM, "users on behalf of McKean, Brandon Scott - mckeanbs" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:mckeanbs@jmu.edu">mckeanbs@jmu.edu</a>> wrote:

<blockquote type="cite">
I'm not entirely sure how to tell that. But if it's where you would see "InitializeAuthenticationContext" in the logs on such a request, then yes, there are 2 requests, behavior that I don't see in the log when I try another SP.
</blockquote>

There should be two audit log entries for these requests, and two web access log records for a GET to the Shibboleth/SSO endpoint with the appropriate parameters.

In which case, there's no way for the IdP to do anything about it unless the SP operator can explain why it's not happy with the first response.

-- Scott

</pre>
</blockquote>
</body>
</html>