<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Hi,</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
This issues seems to have been covered before but the solutions dont seem to apply in this case.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
We have implemented mfa and for most of the cases it works just fine.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
We have an issue however a user logs in the flow evalutes SPNEGOActivation condition,</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
this returns true, so it tries SPNEGO, client signals a problem, SPNEGO results in ReSelectFlow,</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
transitionmap tells it to use authn/Password.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
So it presents this to the user, user fills in the details and is logged in.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
User goes to open another session mfa flow runs again (reuse for mfa flow set to false)</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
SPNEGOActivationCondition: true</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
SPNEGO: ReSelectFlow</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
authn/Passowrd:  reuse previous result</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
mfa: returns ReslectFlow.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
snippet from logs:</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span>2019-04-10 10:25:21,407 - DEBUG - |snipped| [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:221] - Profile Action TransitionMultiFactorAuthentication: MFA flow transition after 'proceed' event to 'authn/SPNEGO' flow<br>
</span>
<div>2019-04-10 10:25:21,408 - DEBUG - |<span style="font-family: Calibri, Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">snipped</span>| [net.shibboleth.idp.authn.spnego.impl.SPNEGOAutoLoginManager:97] - Auto-login
 has been disabled.<br>
</div>
<div>2019-04-10 10:25:21,763 - WARN - |<span style="font-family: Calibri, Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">snipped</span>| [net.shibboleth.idp.authn.spnego.impl.SPNEGOAuthnController:224] - SPNEGO
 authentication problem signaled by client<br>
</div>
<div>2019-04-10 10:25:21,823 - INFO - |<span style="font-family: Calibri, Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">snipped</span>| [net.shibboleth.idp.authn.impl.ValidateExternalAuthentication:130] - Profile
 Action ValidateExternalAuthentication: External authentication produced error message: SPNEGONotAvailable<br>
</div>
<div>2019-04-10 10:25:21,824 - DEBUG - |<span style="font-family: Calibri, Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">snipped</span>| [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:209]
 - Profile Action TransitionMultiFactorAuthentication: Applying MFA transition rule to exit state 'authn/SPNEGO'<br>
</div>
<div>2019-04-10 10:25:21,824 - DEBUG - |<span style="font-family: Calibri, Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">snipped</span>| [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:221]
 - Profile Action TransitionMultiFactorAuthentication: MFA flow transition after 'ReselectFlow' event to 'authn/Password' flow<br>
</div>
<div>2019-04-10 10:25:21,824 - DEBUG - |<span style="font-family: Calibri, Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">snipped</span>| [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:271]
 - Profile Action TransitionMultiFactorAuthentication: Reusing active result for 'authn/Password' flow<br>
</div>
<div>2019-04-10 10:25:21,825 - DEBUG - |<span style="font-family: Calibri, Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">snipped</span>| [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:209]
 - Profile Action TransitionMultiFactorAuthentication: Applying MFA transition rule to exit state 'authn/Password'<br>
</div>
<div>2019-04-10 10:25:21,825 - DEBUG - |<span style="font-family: Calibri, Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">snipped</span>| [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:226]
 - Profile Action TransitionMultiFactorAuthentication: MFA flow completing with event 'ReselectFlow'<br>
</div>
<div>2019-04-10 10:25:21,828 - INFO - |<span style="font-family: Calibri, Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">snipped</span>| [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:138] - Profile
 Action SelectAuthenticationFlow: Moving incomplete flow authn/MFA to intermediate set<br>
</div>
<span>2019-04-10 10:25:21,828 - DEBUG - |<span style="font-family: Calibri, Arial, Helvetica, sans-serif; background-color: rgb(255, 255, 255); display: inline !important">snipped</span>| [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:264] - Profile
 Action SelectAuthenticationFlow: No specific Principals requested</span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span><br>
</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span>from this it would seem that the DefaultMergeStrategy only sees the result from SPNEGO attempt and isnt reusing the password flow.</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span><br>
</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span>Suggestions?</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div id="signature">
<div id="divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<div style="font-family:Tahoma; font-size:13px"><font size="2"><font face="Courier New">--<br>
Aterea Brown, AUT University<br>
Cybersecurity, ICT<br>
Email: atbrown@aut.ac.nz Phone: 9219999 x 6523</font></font></div>
</div>
</div>
</body>
</html>