<div dir="ltr"><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif">Hi,</div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif"><br></div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif"><div class="gmail_default" style="font-size:12.8px"><span style="font-size:12.8px">Can I achieve something like this?</span><br></div><div class="gmail_default" style="font-size:12.8px"><br></div><div class="gmail_default" style="font-size:12.8px">1. Since Service Provider (my web application acts as one), can customize authnrequest by implementing webssoprofileimpl::getauthnrequest, I can add extensions that contain username and password information</div><div class="gmail_default" style="font-size:12.8px"><span style="font-size:12.8px">2. I will customize the IDP to parse the authnrequest, extract the credentials from the extensions and redirect to a custom external authentication flow (implemented by me).</span><br></div><div class="gmail_default" style="font-size:12.8px">4. The request sent to the external authentication by IDP would contain credentials</div><div class="gmail_default" style="font-size:12.8px">5. This external authentication flow that I would have implemented at the IDP would get the credentials from the request and then follow Shibboleth flow/protocol to authenticate the user.</div><div class="gmail_default" style="font-size:12.8px">Could you please let me know if this is a feasible solution? This way I will be able to use my authentication page and also give the authentication control to the IDP.</div></div><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr"><div><br></div><div>Regards,</div><div>Virajitha</div></div></div>
</div>