null principals since upgrade from 2.1.3 to 2.3.2
Kevin P. Foote
kpfoote at iup.edu
Wed Aug 24 17:01:31 BST 2011
If I recall (been a long time) but blackberry devices (using the stock
browser) go through a (goofy) proxied network and don't work well with the
shibboleth flow of events. I think these were showing up similar to
your - null principals.
I've had users of blackberry devices switch to the Opera browser on the
same device and things seem to work..
Again this was a few of OS revs back for blackberries so I have no idea
if this would mean anything today.
I however don't know why your upgrade would have anything to do with this
either.. When I was dealing with this on my end we were using Shib
IdP-2.1.5
------
thanks
kevin.foote
On Tue, 23 Aug 2011, Roberto Ullfig wrote:
-> All these null principals are being generated from blackberry.net
-> connections. Does anyone have an idea of where to start looking at this.
-> I'd also like to know what the user sees on his end when this happens.
-> Does he get into google or does he get an error message?
->
-> On 08/22/2011 10:30 AM, Roberto Ullfig wrote:
-> > Since we upgraded the IDP from 2.1.3 to 2.3.2 we've been getting
-> > occasional null principals. At first I thought it was related to client
-> > cookie IP mismatch (an error that also started appearing in 2.3.2) but I
-> > see some null principals even without the cookie error. Here is one example:
-> >
-> > 08:04:55.638 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:686]
-> > - Creating shibboleth session for principal jarrio2
-> > 08:04:55.639 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:792]
-> > - Adding IdP session cookie to HTTP response
-> > 08:04:55.640 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:701]
-> > - Recording authentication and service information in Shibboleth session
-> > for principal: jarrio2
-> > 08:04:55.641 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:552]
-> > - User jarrio2 authenticated with method
-> > urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
-> > 08:04:55.642 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:161]
-> > - Returning control to profile handler
-> > 08:04:55.643 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:170]
-> > - Redirecting user to profile handler at
-> > https://shibboleth.uic.edu:443/idp/profile/SAML2/Redirect/SSO
-> > 08:04:58.426 - ERROR
-> > [edu.internet2.middleware.shibboleth.idp.session.IdPSessionFilter:182] -
-> > Client sent a cookie from address 74.82.64.144 but the cookie was issued
-> > to address 74.82.64.160
-> > 08:04:58.428 - INFO [Shibboleth-Access:74] -
-> > 20110822T130458Z|74.82.64.144|shibboleth.uic.edu:443|/profile/SAML2/Redirect/SSO|
-> > 08:04:58.429 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:86]
-> > - shibboleth.HandlerManager: Looking up profile handler for request
-> > path: /SAML2/Redirect/SSO
-> > 08:04:58.429 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:97]
-> > - shibboleth.HandlerManager: Located profile handler of the following
-> > type for the request path:
-> > edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler
-> > 08:04:58.430 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:163]
-> > - Incoming request contains a login context, processing as second leg of
-> > request
-> > 08:04:58.430 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:572] -
-> > Unbinding LoginContext
-> > 08:04:58.431 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:598] -
-> > Expiring LoginContext cookie
-> > 08:04:58.432 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:607] -
-> > Removing LoginContext, with key 33887750-3871-4b8e-8dbc-10a42559e03a,
-> > from StorageService partition loginContexts
-> > 08:04:58.432 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.ChainingMetadataProvider:253] -
-> > Checking child metadata provider for entity descriptor with entity ID:
-> > google.com
-> > 08:04:58.433 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:509] -
-> > Searching for entity descriptor with an entity ID of google.com
-> > 08:04:58.434 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:167] -
-> > Metadata document does not contain an EntityDescriptor with the ID
-> > google.com
-> > 08:04:58.435 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.ChainingMetadataProvider:253] -
-> > Checking child metadata provider for entity descriptor with entity ID:
-> > google.com
-> > 08:04:58.436 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:509] -
-> > Searching for entity descriptor with an entity ID of google.com
-> > 08:04:58.436 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:167] -
-> > Metadata document does not contain an EntityDescriptor with the ID
-> > google.com
-> > 08:04:58.437 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.ChainingMetadataProvider:253] -
-> > Checking child metadata provider for entity descriptor with entity ID:
-> > google.com
-> > 08:04:58.438 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:509] -
-> > Searching for entity descriptor with an entity ID of google.com
-> > 08:04:58.438 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.ChainingMetadataProvider:253] -
-> > Checking child metadata provider for entity descriptor with entity ID:
-> > google.com
-> > 08:04:58.439 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:509] -
-> > Searching for entity descriptor with an entity ID of google.com
-> > 08:04:58.440 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:167] -
-> > Metadata document does not contain an EntityDescriptor with the ID
-> > google.com
-> > 08:04:58.441 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.ChainingMetadataProvider:253] -
-> > Checking child metadata provider for entity descriptor with entity ID:
-> > google.com
-> > 08:04:58.441 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:509] -
-> > Searching for entity descriptor with an entity ID of google.com
-> > 08:04:58.442 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:167] -
-> > Metadata document does not contain an EntityDescriptor with the ID
-> > google.com
-> > 08:04:58.443 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.ChainingMetadataProvider:253] -
-> > Checking child metadata provider for entity descriptor with entity ID:
-> > google.com
-> > 08:04:58.443 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:509] -
-> > Searching for entity descriptor with an entity ID of google.com
-> > 08:04:58.444 - DEBUG
-> > [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:127]
-> > - Looking up relying party configuration for google.com
-> > 08:04:58.445 - DEBUG
-> > [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:129]
-> > - Custom relying party configuration found for google.com
-> > 08:04:58.446 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.ChainingMetadataProvider:253] -
-> > Checking child metadata provider for entity descriptor with entity ID:
-> > https://shibboleth.uic.edu/shibboleth
-> > 08:04:58.447 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:509] -
-> > Searching for entity descriptor with an entity ID of
-> > https://shibboleth.uic.edu/shibboleth
-> > 08:04:58.448 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:167] -
-> > Metadata document does not contain an EntityDescriptor with the ID
-> > https://shibboleth.uic.edu/shibboleth
-> > 08:04:58.449 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.ChainingMetadataProvider:253] -
-> > Checking child metadata provider for entity descriptor with entity ID:
-> > https://shibboleth.uic.edu/shibboleth
-> > 08:04:58.449 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:509] -
-> > Searching for entity descriptor with an entity ID of
-> > https://shibboleth.uic.edu/shibboleth
-> > 08:04:58.450 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:167] -
-> > Metadata document does not contain an EntityDescriptor with the ID
-> > https://shibboleth.uic.edu/shibboleth
-> > 08:04:58.451 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.ChainingMetadataProvider:253] -
-> > Checking child metadata provider for entity descriptor with entity ID:
-> > https://shibboleth.uic.edu/shibboleth
-> > 08:04:58.451 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:509] -
-> > Searching for entity descriptor with an entity ID of
-> > https://shibboleth.uic.edu/shibboleth
-> > 08:04:58.452 - DEBUG
-> > [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:167] -
-> > Metadata document does not contain an EntityDescriptor with the ID
-> > https://shibboleth.uic.edu/shibboleth
-> > 08:04:58.454 - DEBUG
-> > [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:101] -
-> > Filtering peer endpoints. Supported peer endpoint bindings:
-> > [urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign,
-> > urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST,
-> > urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact]
-> > 08:04:58.455 - DEBUG
-> > [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:70] -
-> > Selecting endpoint by ACS URL 'https://www.google.com/a/uic.edu/acs' and
-> > protocol binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' for
-> > request 'okmgdanjpoobgjacnhhndgejplkhoenplekkheea' from entity 'google.com'
-> > 08:04:58.456 - DEBUG
-> > [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:472]
-> > - Resolving attributes for principal 'null' for SAML request from
-> > relying party 'google.com'
-> >
-> > Note how the Auth engine knows about jarrio2 but the Profile Handler
-> > doesn't. This problem only occurs from google.com but that could be just
-> > because that's the most popular SP we support. We've had three of these
-> > this morning. I just upgraded tomcat6 to the latest version as well.
-> >
->
->
-> --
-> Roberto Ullfig
-> UIC Research Programmer
->
-> --
-> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
->
More information about the users
mailing list