I'm trying to configure Google Chrome (and Firefox) to authenticate using Active Directory tunneled through ADFS SAML/Kerberos Endpoints and an Apache application using Shibboleth. Here are some settings I have inside each machine.
Active Directory Setting: I am using an Active Directory User Account configured with Kerberos DES Encryption and also have Kerberos preauthentication in Windows Server 2012 r2.
IE Setting: The IE Security Setting for Internet and Trusted Sites has User Authentication set to "Automatic logon with current user name and password" (to automatically login Windows current user). The domains for ADFS and the Apache application are added in the allowed sites.
Windows Server 2012 r2 ADFS Setting: The Windows Server 2012 r2 is configured using ADFS with SAML and Kerberos Endpoints enabled.
Shibboleth SP Setting: The Shibboleth SP runs in Apache, and is configured to use SAML.
What's succesfully happening: The Windows user account can successfully login to any Windows 7 Operating System and above using IE9 and latest. There are no prompts once the Windows user logs in to the Apache application. The Windows user is directed immediately to the Apache Application configured with Shibboleth SP.
What's wrong? Whenever I go to Google Chrome or Firefox, it is not directing immediately to the secure application content page. Instead, it connects the Windows user to an ADFS login screen and login fails (because it seems to be using Kerberos from Active Directory setting, which ADFS does not use on login screen).
Goal: Assuming that Google Chrome takes the security setting from Internet Explorer to use, logging in to the Apache application should work without a hassle.
So, how do I configure Google Chrome properly (or any other configuration) to allow Windows user to login automatically to the Apache application?
Update
Error I get the following error from the Apache application:
openSAML::FatalProfileException at (https://c-app01.contoso.com/Shibboleth.sso/SAML2/POST)
SAML response reported an IdP error.
Error from identity provider:
Status: urn:oasis:names:tc:SAML:2.0:status:Responder