<html>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix">Thank you Vincent, it's a very good
idea<br>
<br>
Marco<br>
<br>
Il 14/12/2016 15:04, Feyaerts Vincent ha scritto:<br>
</div>
<blockquote
cite="mid:656DDF72CA1B7548A28ACEED63737CEB0156A670BA@xmail31.ad.ua.ac.be"
type="cite">
<meta http-equiv="Context-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered
medium)">
<div class="WordSection1">
<p class="MsoNormal"><span>Are you planning to place your IdP
behind a load balancer acting as a reverse proxy? Then you
could just remove the Basic Authentication headers there. In
our case we have our IdP load balanced behind an F5 Big-IP
anyway for failover so it’s easy to remove these headers.
Maybe you have a similar set-up.</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"><span>Kind regards</span></p>
<p class="MsoNormal"><span>Vincent Feyaerts</span></p>
<p class="MsoNormal"><span> </span></p>
<div>
<div>
<p class="MsoNormal"><b><span>From:</span></b><span> users
[<a class="moz-txt-link-freetext" href="mailto:users-bounces@shibboleth.net">mailto:users-bounces@shibboleth.net</a>]
<b>On Behalf Of </b>Marco Naimoli<br>
<b>Sent:</b> woensdag 14 december 2016 14:57<br>
<b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
<b>Subject:</b> Re: Basic Authentication on Password
flow</span></p>
</div>
</div>
<p class="MsoNormal"> </p>
<div>
<p class="MsoNormal">Il 14/12/2016 14:18, <a
moz-do-not-send="true"
href="mailto:users-request@shibboleth.net">
users-request@shibboleth.net</a> ha scritto:</p>
</div>
<blockquote>
<div>
<pre>On 12/14/16, 4:29 AM, "users on behalf of Marco Naimoli" <a moz-do-not-send="true" href="mailto:users-bounces@shibboleth.netonbehalfofmarco.naimoli@unipd.it"><users-bounces@shibboleth.net on behalf of marco.naimoli@unipd.it></a> wrote:</pre>
<pre> </pre>
</div>
<blockquote>
<pre><span class="moz-txt-citetags">> </span>What is the correct and simpler way to disable this feature (hope it's not creating a new flow) ?</pre>
</blockquote>
<pre>There is no supported way. You can file a RFE for that, it would just take a fairly simple patch and you would be able to apply that ahead of time in a manner that would survive upgrades in the future since it would match the change made to the code.</pre>
<pre> </pre>
<pre>I'd be curious why you care about this though.</pre>
<pre> </pre>
<pre>-- Scott</pre>
</blockquote>
<p>I'd like to control to switch on or off this feature; I have
this need because we have a test IDP installation, protected
by a basic auth: users that wants</p>
<p>to use it must authenticate with a personal password. Then
they can do their tests using test users with test passwords;
in a standard IDP installation
</p>
<p>users receive an error about a failed authentication, due to
the check of the basic auth data. It's an aesthetic problem, I
could solve it modifying views,</p>
<p>probably, but I don't want also that anyone can authenticate
"outside" the IDP, to avoid that a site/webapp can be used to
collect user passwords</p>
<p>In the future I could choose to enable this feature, for some
directly controlled SP: that's why I was looking a simple way
(like changing a parameter)</p>
<p>to switch the feature on or off</p>
<p>Thank you very much</p>
<p>Marco</p>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<p><br>
</p>
</body>
</html>