Google Apps using Shibboleth

Paul Hethmon paul.hethmon at clareitysecurity.com
Mon Dec 3 08:38:50 EST 2012


Capture the SAML Response XML by turning on the appropriate logging on the
IdP.

The IdP WARN statement here is not relevant.

Paul

On 12/3/12 8:34 AM, "Prasanna" <PVBalachandar at imperosoftware.com> wrote:

>Thanks Paul....
>
>This is the actual error.
>
>*Google Apps - This account cannot be accessed because we could not parse
>the login request.*
>
>*Log:*
>
>
>13:32:22.372 - INFO [Shibboleth-Access:74] -
>20121203T133222Z|172.16.0.26|dc01.imperoidm.com:443|/profile/SAML2/Redirec
>t/SSO|
>13:32:28.783 - INFO [Shibboleth-Access:74] -
>20121203T133228Z|172.16.0.26|dc01.imperoidm.com:443|/profile/SAML2/Redirec
>t/SSO|
>13:32:29.064 - WARN
>[org.opensaml.saml2.binding.encoding.BaseSAML2MessageEncoder:134] - Relay
>state exceeds 80 bytes, some application may not support this.
>13:32:29.080 - INFO [Shibboleth-Audit:989] -
>20121203T133229Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|nncmbl
>kcijkihpjijcjdhjcchmnblpbdnfmpbglg|google.com|urn:mace:shibboleth:2.0:prof
>iles:saml2:sso|https://dc01.imperoidm.com/idp/shibboleth|urn:oasis:names:t
>c:SAML:2.0:bindings:HTTP-POST|_d7667e60aa114787ce32409656a38bdf|raj|urn:oa
>sis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|principal,tran
>sientId,eduPersonScopedAffiliation,eduPersonTargetedID.old,eduPersonTarget
>edID,||_e2df531bd0634ca7e0180ea931cacc33,|
>
>
>
>
>-----
>Prasanna V B
>--
>View this message in context:
>http://shibboleth.1660669.n2.nabble.com/Google-Apps-using-Shibboleth-tp758
>3436p7583444.html
>Sent from the Shibboleth - Users mailing list archive at Nabble.com.
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net



More information about the users mailing list