<div dir="ltr"><div>Hi Scot</div><div><br></div><div>Thanks for the reply,</div><div><br></div><div>If we change this SP to use Password flow, they will be presented with the IDP login screen, not CAS login screen hence it is not SSO and user experience will be different.</div><div><br></div><div>All the SPs are via CAS except ECP flow for Microsoft, which means, when they login to our Portal via CAS, they can click any SP link which will seamlessly go the SP landing page (because user has already logged in via CAS).</div><div><br></div><div>If I only change one SP to go thru Password flow, they will be presented with a another login screen as the flow is not Shibcas hence having a different user experience.</div><div><br></div><div>So my question is, given this is only happening in Mac, at least to narrow down the issue, within the relying party, is there any way to detect whether request from Mac etc (possibly via userAgent or by othermeans) and direct to the Password Flow, I don't think any need of SSO for this particular function where all happening inside a embedded window.</div><div><br></div><div>Let me know or any other way to approach this.</div><div><br></div><div>As a side note, I am going to query(raise an incident) Microsoft about this particular behavior happening inside Embedded UI view, however I might not have a answer if they ask, what exactly the cookies you think missing etc.</div><div><br></div><div>Thanks</div><div><br></div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Aug 3, 2017 at 11:38 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span>On 8/3/17, 1:01 AM, "users on behalf of Lalith Jayaweera" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:ljayaweera@gmail.com">ljayaweera@gmail.com</a>> wrote:<br>
<br>
> it appears the two re-directions happening form IdP to CAS and CAS to IdP, something getting missed in between<br>
<br>
</span>Yes, by the client, it's probably mangling parameters, cookies, redirects, or all of the above. If you want to know what it's doing, exactly, you are the only one in a position to determine that.<br>
<span><br>
> So is there any way to detect (by some means) this flow and have a different relying Party or any other suggestion, basically no<br>
> issues providing Password flow for this interaction as well.<br>
<br>
</span>You can certainly direct it to use the Password flow for just a single SP and leave all the others alone.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>