<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><br class=""><div><blockquote type="cite" class=""><div class="">On Dec 7, 2018, at 10:12 AM, Peter Schober <<a href="mailto:peter.schober@univie.ac.at" class="">peter.schober@univie.ac.at</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class="">* Howes, Nick <<a href="mailto:N.Howes@warwick.ac.uk" class="">N.Howes@warwick.ac.uk</a>> [2018-12-07 16:49]:<br class=""><blockquote type="cite" class="">Our v3 IdP delegates to our main proprietary login server through<br class="">the RemoteUser flow. This works fine but the login server only knows<br class="">that it's authenticating for the IdP and nothing about what relying<br class="">party the IdP is servicing, so we can't make any business decisions<br class="">on the login screen or even tell the user what they're signing in<br class="">to.<br class=""></blockquote><br class="">I guess the External authn flow could do whatever you needed to?<br class=""><a href="https://wiki.shibboleth.net/confluence/display/IDP30/ExternalAuthnConfiguration" class="">https://wiki.shibboleth.net/confluence/display/IDP30/ExternalAuthnConfiguration</a><br class=""><br class="">-peter<br class="">-- <br class=""></div></div></blockquote><br class=""></div><div>Yes, Unicon's Shib-CAS-Authn3 extension for the IdP (using a separate CAS Server for the authentication) uses that ExternalAuthnConfiguration method, and indeed does pass the SP entityID across. so that can be done as Peter notes.</div><br class=""><div class="">
<div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">--<br class="">Michael A. Grady<br class="">IAM Architect, Unicon, Inc.</div><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" class=""><br class=""></div><br class="Apple-interchange-newline">

</div>
<br class=""></body></html>