<html><head><meta http-equiv="content-type" content="text/html; charset=us-ascii"></head><body style="overflow-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><br><div><br><blockquote type="cite"><div>On May 9, 2024, at 10:15 AM, Cantor, Scott <cantor.2@osu.edu> wrote:</div><br class="Apple-interchange-newline"><div><div><blockquote type="cite">The frustrating part is that it was "failing silently" in that the arguments we had before<br>for v4 just raised a "flow initialization" error without any further detail as to what it did<br>not like.<br></blockquote><br>I'd have to see the log but I think it's more likely that you just couldn't digest a stack trace larger than a terrabyte. They get tricky to read.<br><br>Defining your own beans would have been the way to make it work, yes.<br><br>I suspect it was the HttpClient changes.<br><br>-- Scott<br><br></div></div></blockquote><br></div><div>So still having trouble getting the PreAuth call to Duo working in IdP 5.1.2. There is a ticket open with Duo about it, but the bottom line is that using the same Duo AuthAPi integration being used in IdP 4.x, the PreAuth call is getting back a 401 Unauthorized result, with this response (if I'm reading the log right):</div><div><br></div><div>  "{"code": 40103, "message": "Invalid signature in request credentials", "stat": "FAIL"}"</div><div><br></div>I can share HHTP client DEBUG lines, but is there any change in IdP 5/the HTTP Client/Java 17 that could cause a difference in the calculation of the Authorization: Basic header being sent in the PreAuth call to Duo?  Such that Duo would not like the HMAC-SHA1 value being calculated and sent?<div><br><div>
<div>--<br>Michael A. Grady<br>IAM Architect, Unicon, Inc.</div><div><br></div><br class="Apple-interchange-newline">

</div>
<br></div></body></html>