<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Hi Joey,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">First of all thank you for your detailed answer
</span><span style="font-size:11.0pt;font-family:Wingdings;color:#1F497D">J</span><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I digged in it a lot before posting this message in the forum, even debugged shibboleth in order to understand what is going on in the password flow.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">The password flow is the one that I am using. And from what I see in shibboleth’s code the validation on ldap (which yes this is what I am using), does throw
an event named by InvalidCredentials.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">And the invalid credentials event does have a key in errors.xml. so I don’t think the problem is to identify the event but rather that instead of writing the
error to the response, it will try to move to the next authn flow and then write the “no potentials flow” as a final error to the response.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">By the way - My Client is actually not an end user but a non-web client, some kind of agent which will authenticate to the system. So actually I am not using
the web flows but I am using the ECP flows.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Did you had your experience with web or non-web?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thanks!<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Ayelet.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> Joey Wang [via Shibboleth] [mailto:ml-node+<a href="/user/SendEmail.jtp?type=node&node=7626611&i=0" target="_top" rel="nofollow" link="external">[hidden email]</a>]
<br>
<b>Sent:</b> Thursday, July 07, 2016 5:21 PM<br>
<b>To:</b> Ginni, Ayelet <<a href="/user/SendEmail.jtp?type=node&node=7626611&i=1" target="_top" rel="nofollow" link="external">[hidden email]</a>><br>
<b>Subject:</b> Re: How to insert detailed message in saml response<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div id="yui_3_16_0_ym19_1_1467210484579_248508">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black">Hi, Ayelet,<o:p></o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_248549">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_248551">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black">I had a similar experience as the client needs more detailed error information from IDP. I was able to address it to some degree with helps from Scott.
Not sure if my approach is right or wrong, but I can share my experience with you to see if it helps you.<o:p></o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_249417">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_248790">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black">First of all, Scott is correct in saying that if the end-user cannot do anything to the specific error messages anyway, there is no need to trouble yourself
with it. In my case, I am developing a clinical system that SP needs the detailed messages for auditing purpose as required by law.<o:p></o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_248952">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_248972">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black">Now, it looks like you are using LDAP authentication in your case. Are you writing your own authn flow? If you are not, you may not be able to trap the
LDAP errors because the default authn flow you are using may not do that for you. So if you want those messages to be included in your SAML response, first thing you need to do is to write your own authn flow to generate appropriate events based on the LDAP
error messages.<o:p></o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_249272">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_249273">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black">Second, there are some predefined events and keys in the errors.xml file. If your LDAP errors can not be mapped to a predefined key, you can define your
own events and keys. You can add new events in authn-events-flow.xml file and define the keys in the errors.xml for those events.<o:p></o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_249767">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_249769">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black">Third, you can then modify error-messages.properties file to provide detailed description of the errors.<o:p></o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_250178">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_250180">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black">Joey<o:p></o:p></span></p>
</div>
<div id="yui_3_16_0_ym19_1_1467210484579_249829">
<p class="MsoNormal" style="background:white"><span style="font-family:"Helvetica",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt;background:white"><span style="font-family:"Helvetica",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<div>
<div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-size:10.0pt;font-family:"Arial",sans-serif;color:black">On Wednesday, July 6, 2016 9:06 AM, "Cantor, Scott" <<a href="/user/SendEmail.jtp?type=node&node=7626609&i=0" target="_top" rel="nofollow" link="external">[hidden email]</a>>
wrote:</span><span style="font-family:"Helvetica",sans-serif;color:black"><o:p></o:p></span></p>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt;background:white"><span style="font-family:"Helvetica",sans-serif;color:black"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt;background:white"><span style="font-family:"Helvetica",sans-serif;color:black">> it actually means that somehow the authentication flow mechanism fallback<br>
> should be disabled.<br>
<br>
In effect, yes. It's simply how the system was designed to work and the error handling was never very important since any non-SOAP cases involve error pages that have the ability to dig inside the AuthenticationContext if they care about specific exceptions
recorded.<br>
<br>
> but even if i tried to do it (commented the transition to "ReselectFlow" (at<br>
> system\flows\authn\authn-abstract-flow.xml), i still don't get the invalid<br>
> credentials message in saml response. i am getting something else such as<br>
> "unexpected" message with the event of "InvalidSubjectCanonicalization" or<br>
> something like that. maybe it's a good start (?)<br>
<br>
That means you broke the flow I would imagine, and just didn't change things in a reasonable way.<br>
<br>
> Anyway i wonder why it is not supported in ECP flow, because on UI i can see<br>
> different errors which indicates on different login errors. so how come it<br>
> is not something which we can get in ECP?<br>
<br>
You don't see that in the IdP's UI, you see it in the Password login flow, which is self-contained and loops endlessly inside itself waiting for a successful result.<br>
<br>
The fact that ECP works at all with no additional configuration is a miracle and only works if the client volunteers credentials. Error handling was the least of my concerns getting it to work.<br>
<br>
It also strikes me as irrelevant. It matters to a help desk that an account is locked or whatever, and they should see that information themselves. Either way the user has to contact the same people and get the account reset. I think we generally give users
no help by telling them information they can't act on anyway.<br>
<br>
-- Scott<br>
<br>
-- <br>
To unsubscribe from this list send an email to <a href="" target="_top" rel="nofollow" link="external">dev-unsubscribe@...</a><br>
<br>
<o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
-- <br>
To unsubscribe from this list send an email to <a href="/user/SendEmail.jtp?type=node&node=7626609&i=1" target="_top" rel="nofollow" link="external">
[hidden email]</a> <o:p></o:p></p>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="1" width="100%" noshade="" style="color:#CCCCCC" align="center">
</div>
<div>
<div>
<p class="MsoNormal"><b><span style="font-size:9.0pt;font-family:"Tahoma",sans-serif;color:#444444">If you reply to this email, your message will be added to the discussion below:<o:p></o:p></span></b></p>
</div>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Tahoma",sans-serif;color:#444444"><a href="http://shibboleth.1660669.n2.nabble.com/How-to-insert-detailed-message-in-saml-response-tp7626525p7626609.html" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/How-to-insert-detailed-message-in-saml-response-tp7626525p7626609.html</a>
<o:p></o:p></span></p>
</div>
<div style="margin-top:4.8pt">
<p class="MsoNormal" style="line-height:18.0pt"><span style="font-size:8.5pt;font-family:"Tahoma",sans-serif;color:#666666">To unsubscribe from How to insert detailed message in saml response,
<a href="" target="_top" rel="nofollow" link="external">
click here</a>.<br>
<a href="http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml" target="_top" rel="nofollow" link="external"><span style="font-size:7.0pt;font-family:"Times New Roman",serif">NAML</span></a>
<o:p></o:p></span></p>
</div>
</div>
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/How-to-insert-detailed-message-in-saml-response-tp7626525p7626611.html">RE: How to insert detailed message in saml response</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Developers-f1660781.html">Shibboleth - Developers mailing list archive</a> at Nabble.com.<br/>