<div dir="ltr">Yes, so I have <div><div>idp.authn.flows= Password|Duo|PwdDuo</div></div><div><br></div><div>and </div><div><br></div><div>idp.authn.flows.initial = Password<br></div><div><br></div><div><br></div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr">On Mon, Jan 4, 2016 at 4:42 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 1/4/16, 7:06 PM, "users on behalf of Travis Schmidt" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:travis.schmidt@gmail.com" target="_blank">travis.schmidt@gmail.com</a>> wrote:<br>
<br>
<br>
<br>
>The requested flow is in the regular expression defined in idp.authn.flows.  I am not aware there is another place this needs to be set, and it is working for the CASLoginConfiguration.<br>
<br>
It's the same code, it doesn't care what the profile bean actually is. I don't have a complete picture, but the log was clear that there are no flows available to it once it filters the initial  active set against the authenticationFlows property. So PwdDuo can't be active to start with.<br>
<br>
Is the initial authentication feature is in use?<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>