<div dir="ltr"><div dir="ltr">I am still getting a 302 redirect when I use the Unsolicited SSO Flow. My goal is treat the request like an ECP login.</div><div dir="ltr">Note: I am using an Apache to mask the URI context. The request is coming over /legacyapp and using AJP connection sending to Tomcat on /idp where Shibboleth is installed.</div><div>Is this allowed? Or does Shibboleth intentionally block this?</div><div dir="ltr"> <div>My Authn settings are fairly basic:</div><div><br></div><div><div>idp.authn.flows=RemoteUserInternal</div><div><br></div><div>idp.authn.RemoteUserInternal.nonBrowserSupported=true</div><div>idp.authn.RemoteUserInternal.addDefaultPrincipals=true</div><div>idp.authn.RemoteUserInternal.checkRemoteUser=true</div><div>idp.authn.RemoteUserInternal.proxyRestrictionsEnforced=false</div><div><br></div></div><div>---------------------------------</div><div>What am I missing?</div><div><br></div><div>Note: the /legacyapp is so I can more easily control by each legacy app the specific access controls and integration. Much easier than having everything under /idp.</div><div><br></div><div>Tim </div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Jun 27, 2024 at 12:16 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> The reason I picked the RemoteUserInternal was to reduce<br>
> browser bounce. Since I know the path of the users entering<br>
> the system.<br>
<br>
Fair, reducing the "bounce" was really the only point to it, so that's what it's for.<br>
<br>
-- Scott<br>
<br>
<br>
<br>
<br>
<br>
</blockquote></div>