Testbed configuration: SP secure page constantly refreshing after Authn
Kevin Buckley
kevin.buckley.pawsey.org.au at gmail.com
Wed Sep 20 02:53:40 UTC 2023
In my VM tesbed, I now have an SP (v3), and an IdP (v4) and an
LDAP server that the IdP queries for user details.
Started off using the HTTPpasswd backed on the IdP, and have
been prompted for a username and password stored in the file
and, having entered such details, could then access the secure
page on the SP.
Flusded with that success, the next increment in my
re-familairisation process saw me flip over to having the IdP
talk to an LDAP data connector.
Got to a situation now though, where, if I access the admin/hello
page, things seem to work, in that I am prompted for the username
and password stored in the LDAP, and get a page presenting details
obtained from the LDAP query.
However, when I try to access the protected page on the SP, I am
prompted for the username and password stored in the LDAP as "usual",
- https://idp.168.192.in-addr.arpa/idp/profile/SAML2/Redirect/SSO?execution=e1s2
but, having enetered the requested details, the page in the browser
(running on 192.168.56.1) then just "spins", constantly refreshing
a page that says
Web Login Service - Saving Session Information
Savng login session information to the browser
at the following URI (snapshotted)
- https://idp.168.192.in-addr.arpa/idp/profile/SAML2/Redirect/SSO?execution=e31s2
where the number 31 in the "SSO?execution=e31s2" above is being
incremented with each refresh.
Any /thoughts/similar experiences/ ?
I thought to present some logs from the various component parts
(longer lines broken for clarty) in case they flag something up
to the more familiar.
On the IdP
idp-process.log
...
2023-09-20 09:39:15,051 - 192.168.56.1 -
INFO [Shibboleth-Audit.SSO:338] - 192.168.56.1|
2023-09-20T01:39:14.879970Z|
2023-09-20T01:39:15.051226Z|
kbuckley|https://rocky8-02.168.192.in-addr.arpa/shibboleth|
_815d27e1eb26d1bd636a34c537ad2b0e|
password|
2023-09-20T01:39:12.489Z|
schacHomeOrganization|
AAdzZWNyZX...|
transient|
true|
false|
AES128-GCM|
Redirect|
POST|
|
Success|
|
71c12ad...hex...|
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/117.0
2023-09-20 09:39:15,133 - 192.168.56.1 -
INFO [net.shibboleth.idp.authn.impl.FinalizeAuthentication:196] -
Profile Action FinalizeAuthentication: Principal kbuckley authenticated
On the SP
httpd/ssl_access_log
...
192.168.56.1 - - [20/Sep/2023:09:39:14 +0800] "POST /Shibboleth.sso/SAML2/POST HTTP/1.1" 302 228
192.168.56.1 - - [20/Sep/2023:09:39:15 +0800] "POST /Shibboleth.sso/SAML2/POST HTTP/1.1" 302 228
shibboleth/shibd.log
2023-09-20 09:39:14 INFO Shibboleth.AttributeExtractor.XML [1] [default]:
skipping SAML 2.0 Attribute with Name: urn:oid:1.3.6.1.4.1.25178.1.2.9
2023-09-20 09:39:14 INFO Shibboleth.SessionCache [1] [default]:
new session created: ID (_d5422de721b15c4d12c7664758e41042)
IdP (https://idp.168.192.in-addr.arpa/idp/shibboleth)
Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (192.168.56.1)
2023-09-20 09:39:15 INFO Shibboleth.AttributeExtractor.XML [1] [default]:
skipping SAML 2.0 Attribute with Name: urn:oid:1.3.6.1.4.1.25178.1.2.9
2023-09-20 09:39:15 INFO Shibboleth.SessionCache [1] [default]:
new session created: ID (_bd7f2448d535116bed430c0fe15c876b)
IdP (https://idp.168.192.in-addr.arpa/idp/shibboleth)
Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (192.168.56.1)
shibboleth/transaction.log
2023-09-20 09:39:14|Shibboleth-TRANSACTION.Login|
|
_d5422de721b15c4d12c7664758e41042|
https://idp.168.192.in-addr.arpa/idp/shibboleth|
_9fa6eebef92ed5d9c5386d2082ef419a|
urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|
2023-09-20T09:39:12|
|
AAdzZWNyZX...|
urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|
|
urn:oasis:names:tc:SAML:2.0:status:Success|
|
|Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/117.0|192.168.56.1
2023-09-20 09:39:14|Shibboleth-TRANSACTION.AuthnRequest|||https://idp.168.192.in-addr.arpa/idp/shibboleth||||||urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect||||||
2023-09-20 09:39:15|Shibboleth-TRANSACTION.Login|
|
_bd7f2448d535116bed430c0fe15c876b|
https://idp.168.192.in-addr.arpa/idp/shibboleth|
_815d27e1eb26d1bd636a34c537ad2b0e|
urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|
2023-09-20T09:39:12|
|
AAdzZWNyZXQxAghiioctEcT/P7jokXsoCRdLIMyGdHBRQA3w7/QKxWv+IGBQTp9HJl9zOnTz3Ks0iNrQqvbU8CIRDiMWnQ8CBRQl1cP4BeQZDUuwSLYUA2cq0FZOUi94g/GlaTaHjZAztM+ux0TN1bt2E6cKkjXQAF9LQRdA5Fgc|
urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|
|
urn:oasis:names:tc:SAML:2.0:status:Success|
|
|
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/117.0|
192.168.56.1
2023-09-20 09:39:15|Shibboleth-TRANSACTION.AuthnRequest|||https://idp.168.192.in-addr.arpa/idp/shibboleth||||||urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect||||||
Kevin Buckley
More information about the dev
mailing list