<html><head><meta http-equiv="content-type" content="text/html; charset=us-ascii"></head><body style="overflow-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><br><div><br><blockquote type="cite"><div>On May 9, 2024, at 7:27 AM, Cantor, Scott <cantor.2@osu.edu> wrote:</div><br class="Apple-interchange-newline"><div><div><blockquote type="cite">Thanks Scott and Chris for the responses, I did get it working, by defining our own copy<br>of the (NonBrowser) DuoIntegration and PreAuth beans (that the IdP has now in duo<br>-oidc-authn-beans.xml) -- with our own Bean IDs of course -- and then referencing those<br>beans in the map we have in mfa-auth-config.xml. So now working again as it did in IdP<br>4.x.<br></blockquote><br>FWIW, while the classes themselves were of course in the IdP itself, the beans wouldn't have been accessble from the MFA flow's config file/context. So short of defining them yourself as you did, I don't know how it would have worked before.<br><br>That's partly what I meant by "not really supported".<br><br>We do not have the AuthAPI beans defined globally for shared use but the Admin API beans are globally shared for that reason (thanks to Steven Premeau pointing it out).<br><br>-- Scott<br><br></div></div></blockquote><br></div><div>We were defining our own beans in v4, but just as part of the Map entry value in our "checkMap" within mfa-authn-config.xml. It may just be that I wasn't updating the httpClient-related property values correctly for the PreAuth bean. The frustrating part is that it was  "failing silently" in that the arguments we had before for v4 just raised a "flow initialization" error without any further detail as to what it did not like.</div><br><div>
<div>--<br>Michael A. Grady<br>IAM Architect, Unicon, Inc.</div><div><br></div><br class="Apple-interchange-newline">

</div>
<br></body></html>