<div dir="ltr"><div>Hello, I'm using MFA for authentication on my Shibboleth IDP installation; it is configured to <br></div><div>call authn/RemoteUser and then to go on with attribute resolution. It works, and some attributes come from authn/RemoteUser http headers (there's a reverse proxy apache in front of the shibboleth IDP installation)<br></div><div>I'm trying to use the impersonate intercept and it works as expected, but when I impersonate</div><div>another user after about 20-25 seconds the attributes  using the http headers are not created again, because those http headers are emptied. Before 20-25 seconds there's no problem at all.<br></div><div>Any suggestion ?<br></div><div>Shibboleth IDP is a 3.4.6 installation (+jetty), apache a 2.4.x<br></div><div>Thank you</div><div>Marco<br></div><div><br></div><div><br></div></div>