<div dir="ltr"><div dir="ltr"><div>We're retiring our legacy SSO in favor of allowing Shibboleth to handle it's own authentication.  Currently, Cosign handles both password and Duo.</div><div><br></div><div>I'm playing with the Duo flow (being invoked by the MFA flow), and the default Duo velocity template includes a link labeled "Cancel this request".  It seems to leave the user at an error page:</div><div dir="ltr"><div><br></div><div>    opensaml::FatalProfileException<br></div><div>    ...</div><div><div>    Error from identity provider:</div><div><br></div><div>        Status: urn:oasis:names:tc:SAML:2.0:status:Requester</div><div>        Sub-Status: urn:oasis:names:tc:SAML:2.0:status:NoAuthnContext</div><div>        Message: An error occurred.</div></div><div><br></div><div>Is there a more user friendly destination / message that could be displayed?</div><div>Or do most people just remove the "Cancel this request" link from the template when they deploy Duo?</div><div><br></div><div>Liam</div></div></div></div>