<div dir="auto"><div><br><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Sep 17, 2019, 10:56 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 9/17/19, 10:39 PM, "users on behalf of Jeffrey Williams" <<a href="mailto:users-bounces@shibboleth.net" target="_blank" rel="noreferrer">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:jfwillia@uncg.edu" target="_blank" rel="noreferrer">jfwillia@uncg.edu</a>> wrote:<br>
<br>
> I think this is doing what I intend, but I'd also like it to throw an error page on the IdP side if the SP requires MFA and the<br>
> user is not enrolled.<br>
<br>
If they don't want to handle the error, they shouldn't be asking for it. That's why the standard defines a specific status code for it.<br></blockquote></div></div><div dir="auto"><br></div><div dir="auto">We'll stick to the standard, then, and let the vendor do the error handling. Thanks so much!</div><div dir="auto"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
<br>
<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank" rel="noreferrer">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div></div></div>