<div dir="ltr">Looks like things authenticating, just that, instead of going to CAS login screen now everything goes to LDAP login screen which is in IdP<div><br></div><div>Do I have to again use p:authenticationFlows in the profile </div><div><br></div><div>I thought I dont have to use it,</div><div><br></div><div>Please advice any change of properties required</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Jul 19, 2017 at 2:52 PM, Lalith Jayaweera <span dir="ltr"><<a href="mailto:ljayaweera@gmail.com" target="_blank">ljayaweera@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Hi Scot,<div><br></div><div>Thanks for the detailed answer, we had ECP with Apache (SASL) authentication on V2 working with no issues hence was trying the same with V3,  Before I try out password flow, just to give you an update, I did below with the current setup but same failure....however not going to go too much into it as I already starting configuring password flow.</div><div><br></div><div>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"> p:authenticationFlows="#{{'<wbr>RemoteUserInternal'}}" in ECP profile<span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><span> </span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">with
idp.authn.flows=Shibcas|<wbr>RemoteUserInternal  in idp.properties but failed.<span></span></span></p><p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><br></span></p><p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">With SASL we have more control over the LDAP filters, because in Office 365 ECP, only local part of UPN will hit the IDP,</span></p><p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><br></span></p><p class="MsoNormal"><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:11pt">I am going to try below to enable the </span><span style="font-size:14.6667px">password</span><span style="font-size:11pt"> flow and see. Please advice if anything wrong in my steps</span></font></p><p class="MsoNormal"><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:11pt"><br></span></font></p><p class="MsoNormal"><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:11pt">*Remove above </span></font><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px">authenticationFlows from the ECP profile</span></p><p class="MsoNormal"><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px">* change idp.properties  to </span><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px">idp.authn.flows=Shibcas|<wbr>Password</span></p><p class="MsoNormal"><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px">* remove the Apache configuration which protected ECP URL</span></font></p><p class="MsoNormal"><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px"><br></span></p><p class="MsoNormal"><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px">and configure the ldap.properties to do the authentication,  so I believe similar to SASL I can have something like below for auth filter in ldap.properties because I only receive local part of UPN and in our ldap there is no such direct attribute to bind, </span></font></p><p class="MsoNormal"><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px"><br></span></p><p class="MsoNormal"><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px">idp.authn.LDAP.userFilter = (mail={<a href="mailto:user%7D@ourdomain.com" target="_blank">user}@ourdomain.com</a>)</span></font><br></p><p class="MsoNormal"><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></p><p class="MsoNormal"><span style="font-size:14.6667px;color:rgb(31,73,125);font-family:Calibri,sans-serif">Please advice anything wrong or require any other configuration </span><br></p><p class="MsoNormal"><span style="font-size:14.6667px;color:rgb(31,73,125);font-family:Calibri,sans-serif"><br></span></p><p class="MsoNormal"><span style="font-size:14.6667px;color:rgb(31,73,125);font-family:Calibri,sans-serif"><br></span></p><p class="MsoNormal"><span style="font-size:14.6667px;color:rgb(31,73,125);font-family:Calibri,sans-serif">Thanks</span></p><p class="MsoNormal"><span style="font-size:14.6667px;color:rgb(31,73,125);font-family:Calibri,sans-serif"><br></span></p><p class="MsoNormal"><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></p><p class="MsoNormal"><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></p><p class="MsoNormal"><font color="#1f497d" face="Calibri, sans-serif"><span style="font-size:14.6667px"><br></span></font></p><p class="MsoNormal"><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:14.6667px"><br></span></p><p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><br></span></p><p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><br></span></p></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div></div><div class="HOEnZb"><div class="h5"><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Jul 19, 2017 at 2:28 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Also, it goes without saying that you can't just do things blindly here. I made a suggestion in context. When I said to tell the ECP profile to direct itself to use RemoteUserInternal, that was with the implicit assumption that you were going to configure that flow in accordance with the documentation, and enable it via the idp.login.flows property expression. If you did none of these things, then, no, it's not going to do anything but fail.<br>
<br>
The V3 ECP support is designed to be used with the Password flow to make it simple for people to deploy without extra work since most people were using the password support in V2.<br>
<br>
The authenticationFlows property isn't normally something you would set, but I think it's the most natural way to get the system to support two separate "isolated" flows that work separately for browser and ECP. You would configure each login flow separately, but correctly, enable both in the property setting that turns on the flows, and then direct ECP to use one and the browser-based flows like SAML2.SSO to use the other. Then they're both functioning essentially in isolation but together in the system at the same time.<br>
<br>
I have never done this specifically, but that's my general guess as to the simplest way to do it with the least chance to introduce side effects.<br>
<span class="m_6174949618508163558HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="m_6174949618508163558HOEnZb"><div class="m_6174949618508163558h5"><br>
On 7/18/17, 11:31 AM, "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br>
<br>
On 7/17/17, 11:34 PM, "users on behalf of Lalith Jayaweera" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:ljayaweera@gmail.com" target="_blank">ljayaweera@gmail.com</a>> wrote:<br>
<br>
> you mean something like below, but same failure result ....with authentication issue<br>
<br>
Then you need to use logs, read the documentation, determine what actually is going wrong, etc. You are running a complicated set of options and approaches and that means you will have to learn and understand much more than somebody following the more advisable, out of the box, approaches.<br>
<br>
-- Scott<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.n<wbr>et</a><br>
</div></div></blockquote></div><br></div>
</div></div></blockquote></div><br></div>