Testbed configuration: SP secure page constantly refreshing after Authn

Kevin Buckley kevin.buckley.pawsey.org.au at gmail.com
Wed Sep 20 02:53:40 UTC 2023


In my VM tesbed, I now have an SP (v3), and an IdP (v4) and an
LDAP server that the IdP queries for user details.

Started off using the HTTPpasswd backed on the IdP, and have
been prompted for a username and password stored in the file
and, having entered such details, could then access the secure
page on the SP.

Flusded with that success, the next increment in my
re-familairisation process saw me flip over to having the IdP
talk to an LDAP data connector.

Got to a situation now though, where, if I access the admin/hello
page, things seem to work, in that I am prompted for the username
and password stored in the LDAP, and get a page presenting details
obtained from the LDAP query.

However, when I try to access the protected page on the SP, I am
prompted for the username and password stored in the LDAP as "usual",

    - https://idp.168.192.in-addr.arpa/idp/profile/SAML2/Redirect/SSO?execution=e1s2

but, having enetered the requested details, the page in the browser
(running on 192.168.56.1) then just "spins", constantly refreshing
a page that says


Web Login Service - Saving Session Information

Savng login session information to the browser

at the following URI (snapshotted)

    - https://idp.168.192.in-addr.arpa/idp/profile/SAML2/Redirect/SSO?execution=e31s2

where the number 31 in the "SSO?execution=e31s2" above is being
incremented with each refresh.

Any /thoughts/similar experiences/ ?


I thought to present some logs from the various component parts
(longer lines broken for clarty) in case  they flag something up
to the more familiar.

On the IdP

idp-process.log
...
2023-09-20 09:39:15,051 - 192.168.56.1 -
INFO [Shibboleth-Audit.SSO:338] - 192.168.56.1|
2023-09-20T01:39:14.879970Z|
2023-09-20T01:39:15.051226Z|
kbuckley|https://rocky8-02.168.192.in-addr.arpa/shibboleth|
_815d27e1eb26d1bd636a34c537ad2b0e|
password|
2023-09-20T01:39:12.489Z|
schacHomeOrganization|
AAdzZWNyZX...|
transient|
true|
false|
AES128-GCM|
Redirect|
POST|
|
Success|
|
71c12ad...hex...|
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/117.0

2023-09-20 09:39:15,133 - 192.168.56.1 -
INFO [net.shibboleth.idp.authn.impl.FinalizeAuthentication:196] -
  Profile Action FinalizeAuthentication: Principal kbuckley authenticated



On the SP


httpd/ssl_access_log
...
192.168.56.1 - - [20/Sep/2023:09:39:14 +0800] "POST /Shibboleth.sso/SAML2/POST HTTP/1.1" 302 228
192.168.56.1 - - [20/Sep/2023:09:39:15 +0800] "POST /Shibboleth.sso/SAML2/POST HTTP/1.1" 302 228


shibboleth/shibd.log

2023-09-20 09:39:14 INFO Shibboleth.AttributeExtractor.XML [1] [default]:
  skipping SAML 2.0 Attribute with Name: urn:oid:1.3.6.1.4.1.25178.1.2.9

2023-09-20 09:39:14 INFO Shibboleth.SessionCache [1] [default]:
  new session created: ID (_d5422de721b15c4d12c7664758e41042)
  IdP (https://idp.168.192.in-addr.arpa/idp/shibboleth)
  Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (192.168.56.1)

2023-09-20 09:39:15 INFO Shibboleth.AttributeExtractor.XML [1] [default]:
  skipping SAML 2.0 Attribute with Name: urn:oid:1.3.6.1.4.1.25178.1.2.9

2023-09-20 09:39:15 INFO Shibboleth.SessionCache [1] [default]:
  new session created: ID (_bd7f2448d535116bed430c0fe15c876b)
  IdP (https://idp.168.192.in-addr.arpa/idp/shibboleth)
  Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (192.168.56.1)

shibboleth/transaction.log


2023-09-20 09:39:14|Shibboleth-TRANSACTION.Login|
|
_d5422de721b15c4d12c7664758e41042|
https://idp.168.192.in-addr.arpa/idp/shibboleth|
_9fa6eebef92ed5d9c5386d2082ef419a|
urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|
2023-09-20T09:39:12|
|
AAdzZWNyZX...|
urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|
|
urn:oasis:names:tc:SAML:2.0:status:Success|
|
|Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/117.0|192.168.56.1

2023-09-20 09:39:14|Shibboleth-TRANSACTION.AuthnRequest|||https://idp.168.192.in-addr.arpa/idp/shibboleth||||||urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect||||||

2023-09-20 09:39:15|Shibboleth-TRANSACTION.Login|
|
_bd7f2448d535116bed430c0fe15c876b|
https://idp.168.192.in-addr.arpa/idp/shibboleth|
_815d27e1eb26d1bd636a34c537ad2b0e|
urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|
2023-09-20T09:39:12|
|
AAdzZWNyZXQxAghiioctEcT/P7jokXsoCRdLIMyGdHBRQA3w7/QKxWv+IGBQTp9HJl9zOnTz3Ks0iNrQqvbU8CIRDiMWnQ8CBRQl1cP4BeQZDUuwSLYUA2cq0FZOUi94g/GlaTaHjZAztM+ux0TN1bt2E6cKkjXQAF9LQRdA5Fgc|
urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|
|
urn:oasis:names:tc:SAML:2.0:status:Success|
|
|
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/117.0|
192.168.56.1

2023-09-20 09:39:15|Shibboleth-TRANSACTION.AuthnRequest|||https://idp.168.192.in-addr.arpa/idp/shibboleth||||||urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect||||||


Kevin Buckley



More information about the dev mailing list