<div dir="ltr">Hi,<div><br></div><div>At this point we are using LDAP for authentication.</div><div>It seems that we should also support X509 authentication - for clients that are not using browser to access a protected resource.</div><div><br></div><div>Looking at <a href="https://wiki.shibboleth.net/confluence/display/IDP30/X509InternalAuthnConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/X509InternalAuthnConfiguration</a></div><div>there is a note about:</div><div><span style="color:rgb(51,51,51);font-size:14px;line-height:20px">"this flow doesn't redirect to a protected path; rather, the path of the requested profile flow has to be protected, which typically will trigger as soon as the client makes its first request. "</span><br></div><div><br></div><div>I don't get here what happens after client gets authenticated?</div><div>What mechanisms are in place (maybe something that is not part of Shibboleth) to make sure that the authenticated client can then do something (e.g. access some URL or something else)</div><div><br></div><div>-Vedran</div></div>