Delegation IDP internal error

Eddie Harari eddie.harari at gmail.com
Sun Jul 29 11:35:52 EDT 2012


Hi ,

   I am getting the following error when my sp try to authenticate
using delegation to my back service sp:

21:25:35.296 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.authn.AudienceRestrictionConditionValidator:93]
- Matched valid audience: https://shib.zehut.org/idp/shibboleth
21:25:35.296 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.authn.AbstractSubjectConfirmationValidator:113]
- Evaluating SubjectConfirmationData NotBefore 'null' against 'skewed
now' time '2012-07-29T18:30:35.296Z'
21:25:35.296 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.authn.AbstractSubjectConfirmationValidator:140]
- Evaluating SubjectConfirmationData NotOnOrAfter 'null' against
'skewed now' time '2012-07-29T18:20:35.296Z'
21:25:35.296 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.authn.HolderOfKeySubjectConfirmationValidator:100]
- Attempting holder-of-key subject confirmation
21:25:35.296 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.authn.HolderOfKeySubjectConfirmationValidator:157]
- SubjectConfirmationData xsi:type was either null or matched
{urn:oasis:names:tc:SAML:2.0:assertion}KeyInfoConfirmationDataType
21:25:35.296 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.authn.HolderOfKeySubjectConfirmationValidator:226]
- Found '1' KeyInfo children of SubjectConfirmationData
21:25:35.296 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.authn.HolderOfKeySubjectConfirmationValidator:246]
- KeyInfo contained no KeyValue children, skipping KeyValue match
21:25:35.297 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.authn.HolderOfKeySubjectConfirmationValidator:305]
- Attempting to match KeyInfo X509Data to supplied X509Certificate
param
21:25:35.297 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.authn.HolderOfKeySubjectConfirmationValidator:318]
- Matched X509Certificate
21:25:35.297 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.authn.HolderOfKeySubjectConfirmationValidator:131]
- Successfully matched certificate in subject confirmation data to
supplied cert param
21:25:35.298 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.ws.security.decoder.securitypolicy.WSSecuritySAML20AssertionTokenRule:177]
- Assertion token validation result was: VALID
21:25:35.298 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.profile.LibertyIDWSFSSOSProfileHandler:534]
- Decoded request from relying party 'http://drupal.zehut.org'
21:25:35.298 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128]
- Looking up relying party configuration for http://drupal.zehut.org
21:25:35.298 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134]
- No custom relying party configuration found for
http://drupal.zehut.org, looking up configuration based on metadata
groups.
21:25:35.298 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157]
- No custom or group-based relying party configuration found for
http://drupal.zehut.org. Using default relying party configuration.
21:25:35.298 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128]
- Looking up relying party configuration for http://drupal.zehut.org
21:25:35.298 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134]
- No custom relying party configuration found for
http://drupal.zehut.org, looking up configuration based on metadata
groups.
21:25:35.299 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157]
- No custom or group-based relying party configuration found for
http://drupal.zehut.org. Using default relying party configuration.
21:25:35.299 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128]
- Looking up relying party configuration for http://sp.zehut.org/
21:25:35.299 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:130]
- Custom relying party configuration found for http://sp.zehut.org/
21:25:35.299 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.profile.LibertyIDWSFSSOSProfileHandler:385]
- Checking whether request presenter 'http://sp.zehut.org/' allows
delegate token issuance to requester 'http://drupal.zehut.org'
21:25:35.299 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128]
- Looking up relying party configuration for http://sp.zehut.org/
21:25:35.299 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:130]
- Custom relying party configuration found for http://sp.zehut.org/
21:25:35.300 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.profile.LibertyIDWSFSSOSProfileHandler:410]
- Token did not have delegation chain, this must be initial delegation
request
21:25:35.300 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128]
- Looking up relying party configuration for http://sp.zehut.org/
21:25:35.300 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:130]
- Custom relying party configuration found for http://sp.zehut.org/
21:25:35.300 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.profile.LibertyIDWSFSSOSProfileHandler:898]
- Attempting to resolve principal name from assertion token presented
by 'http://sp.zehut.org/', with NameID format
'urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified' and value
'eddie'
21:25:35.300 - DEBUG
[edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:539]
- Resolving principal name for subject of SAML request 'null' from
relying party 'http://sp.zehut.org/'
21:25:35.300 - DEBUG
[edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.ShibbolethAttributeResolver:201]
- Resolving principal name from name identifier of format:
urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
21:25:35.300 - DEBUG
[edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.ShibbolethAttributeResolver:222]
- Using principal connector saml1Unspec to resolve principal name.
21:25:35.300 - WARN
[edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:551]
- Error resolving principal name for SAML request 'null' from relying
party 'http://sp.zehut.org/'. Cause: No information associated with
transient identifier: eddie
21:25:35.300 - WARN
[edu.internet2.middleware.shibboleth.idp.ext.delegation.profile.LibertyIDWSFSSOSProfileHandler:911]
- Error resolving principal name from assertion token presented by
'http://sp.zehut.org/', with NameID format
'urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified' and value
'eddie'
21:25:35.301 - DEBUG
[edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:778]
- Encoding response to SAML request _9fa01bed9084bbd7011325c0b6fdf7ef
from relying party http://drupal.zehut.org
21:25:35.302 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.ws.security.encoder.handler.AddTimestampHandler:131]
- Processing addition of outbound WS-Security Timestamp
21:25:35.302 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.ws.security.encoder.handler.AddTimestampHandler:136]
- WS-Security Timestamp Created value added was:
2012-07-29T18:25:35.301Z
21:25:35.302 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.ws.security.encoder.handler.AddTimestampHandler:157]
- Resulting WS-Security Timestamp was non-null, adding to outbound
envelope
21:25:35.302 - DEBUG
[edu.internet2.middleware.shibboleth.idp.ext.delegation.ws.security.encoder.handler.AddTimestampHandler:160]
- Security header was null, buildin

any idea what the problem might be ?


More information about the users mailing list