<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<meta content="text/html; charset=UTF-8">
<style type="text/css" style="">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
</style>
<div dir="ltr">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Arial,Helvetica,sans-serif">
<p></p>
<div>I guess I want to fail the request, not necessarily authentication. I will take a look at ContextCheckInterceptConfiguration. </div>
<div><br>
</div>
<div>We use Kerberos for initial authentication, if that changes anything. </div>
<div><br>
</div>
<div>Thank you, </div>
<div>Olga.</div>
<br>
<p></p>
<div id="x_Signature">
<div id="x_divtagdefaultwrapper" style="font-size:12pt; color:#000000; background-color:#FFFFFF; font-family:Calibri,Arial,Helvetica,sans-serif">
<div style="font-family:Tahoma; font-size:13px">
<div style="font-family:Tahoma; font-size:13px"><br>
</div>
</div>
</div>
</div>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober <peter.schober@univie.ac.at><br>
<b>Sent:</b> Wednesday, November 16, 2016 10:18:35 AM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Re: fail authentication when attribute is not available?</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">* Cantor, Scott <cantor.2@osu.edu> [2016-11-16 17:14]:<br>
> Failing authentication and failing specific requests are different<br>
> and you have to be aware of what you want.<br>
<br>
Right, thanks for pointing that out.<br>
<br>
> Failing authentication itself requires custom development or more<br>
> likely would be handled with the MFA flow in 3.3.<br>
<br>
I meant to write that failing authentication should be done by the<br>
authentcation sytem/method used. For LDAP that might be a more complex<br>
LDAP search filter, etc., but the OP didn't mention what specifically<br>
they was using other than "not LDAP".<br>
-peter<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
<br>
</div>
</span></font>
</body>
</html>