<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto">Hello,<div><br></div><div>Reaching out for help. I have the following request / response sequence in our SAML proxy setup of Shibboleth IDP. </div><div><br></div><div><b><u>Scenario</u></b>:</div><div>SP <=> Downstream IDP <=> Upstream IDP <=> Third Party IDP</div><div><br></div><div>In above, “Downstream IDP” is Shibboleth IDP v4.2</div><div><br></div><div>In this process, the SP first requests authcontext of “Password Protected“ in the auth request. The same gets preserved up to Third Party IDP which completes the AuthN and returns a custom authcontextclassref. This value is preserved up to the Downstream IDP that returns an error to the SP due to the difference in contextclassref between its  request and response from Upstream IDP.  </div><div><br></div><div><b><u>Question</u></b>: Is there a configuration in Shibboleth IDP that allows me to disable this check and simply return the originally requested contextclassref (password protected) ? </div><div><br><br><div dir="ltr"><div>Thanks,</div><div>Prasanna</div>(<span style="background-color: rgba(255, 255, 255, 0);">Sent from mobile device, please ignore typos</span>)</div></div></body></html>