<div dir="ltr"><div>Hi all, sorry, I've found the (forgotten) timeout setting on the RemoteUser auth side, it was the cause of the <br></div><div>strange behaviour<br></div><div>Thanks</div><div>Marco<br></div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">Il giorno gio 20 mag 2021 alle ore 11:47 Marco Naimoli <<a href="mailto:marco.naimoli@unipd.it">marco.naimoli@unipd.it</a>> ha scritto:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div>Hello, I'm using MFA for authentication on my Shibboleth IDP installation; it is configured to <br></div><div>call authn/RemoteUser and then to go on with attribute resolution. It works, and some attributes come from authn/RemoteUser http headers (there's a reverse proxy apache in front of the shibboleth IDP installation)<br></div><div>I'm trying to use the impersonate intercept and it works as expected, but when I impersonate</div><div>another user after about 20-25 seconds the attributes  using the http headers are not created again, because those http headers are emptied. Before 20-25 seconds there's no problem at all.<br></div><div>Any suggestion ?<br></div><div>Shibboleth IDP is a 3.4.6 installation (+jetty), apache a 2.4.x<br></div><div>Thank you</div><div>Marco<br></div><div><br></div><div><br></div></div>
</blockquote></div>