Server 500 error upon receipt of assertion

Mike Flynn shibbolethlynda at yahoo.com
Tue Oct 2 15:31:12 EDT 2012


Oops - wrong metadata definition there - It's actually this: <MetadataProvider type="XML" uri="https://idp2.unr.edu/idp/shibboleth" />


________________________________
 From: Mike Flynn <shibbolethlynda at yahoo.com>
To: Shib Users <users at shibboleth.net> 
Sent: Tuesday, October 2, 2012 12:26 PM
Subject: Server 500 error upon receipt of assertion
 

I have a school that is a member of InCommon but have spun up a new Idp that is not part of InCommon.

So I set them up as a private federation (I have setup lots of these before with no issues) by adding the following session initiator config:

            <SessionInitiator type="Chaining" Location="/Login" isDefault="true" id="Intranet" relayState="cookie" entityID="https://idp2.unr.edu/idp/shibboleth">
                <SessionInitiator type="SAML2" acsIndex="1" acsByIndex="false" template="bindingTemplate.html"/>
                <SessionInitiator type="Shib1" acsIndex="5"/>
            </SessionInitiator>

And metadata:

<MetadataProvider type="XML" uri="https://cas.masdar.ac.ae/idp/profile/Metadata/SAML" />

When they attempt to authenticate to me, a redirect back to their site occurs for username/pass challenge.  Upon sign in, they redirect back to me with this assertion:

<?xml version="1.0" encoding="UTF-8"?><saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_25001fe90a27cf014fd8c8627a5915f4" IssueInstant="2012-10-02T18:32:41.984Z" Version="2.0" xmlns:xs="http://www.w3.org/2001/XMLSchema">
   <saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://idp2.unr.edu/idp/shibboleth</saml2:Issuer>
   <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
      <ds:SignedInfo>
         <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
         <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
         <ds:Reference URI="#_25001fe90a27cf014fd8c8627a5915f4">
            <ds:Transforms>
               <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
               <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
                  <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>
               </ds:Transform>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>6wzppl9E+qGg9H8LjCdEr8wG4Qg=</ds:DigestValue>
         </ds:Reference>
      </ds:SignedInfo>
      <ds:SignatureValue>e1v32pRcuykzLQ+0Vifc65pjf1PS/jAniU8onUmVOi7+tzx6B/lpwZzrAR59xLI+9pZHrGCjpLHOgUsKQynoKg1uAxymB91+Z0aqkUN1DpPCqBoeOMrwbwT4iHHoq1q0WBbIxX1/bdd7QRi7QsVs1mwpPvQiJDkxOAIyOg5s9kjw4MeUkcCIR3rzE54PFmX2u2Y4Gsi6ZOirriTufvKLh+6gFzsTLaUjjkLy5KSLz5Ihv3Z92Ch+joXMNo0YgUA/Dg/h+vIRBZ6ePdhRoG3Kp6gYOGr14G0yD02ngcCMrWsLVsY5b5rwS8rrcw5p7JvjCQltb8CyKzW57PqbLC+wPQ==</ds:SignatureValue>
      <ds:KeyInfo>
         <ds:X509Data>
            <ds:X509Certificate>MIIDIzCCAgugAwIBAgIJAKe3lmdIL/y1MA0GCSqGSIb3DQEBBQUAMBUxEzARBgNVBAMTCmFhLnVu
ci5lZHUwHhcNMTAxMDIxMTczNjQ4WhcNMTMxMDIwMTczNjQ4WjAVMRMwEQYDVQQDEwphYS51bnIu
ZWR1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyjOvGetymBixa0PMEgvFp7GqUp+Y
rdF0RRgTfAFv9RwuysFMYDlqMjcrsqrmQnQrhs3OEkJj90BZN3d8rt03aVo3fy+o3gxswMkjGzF5
cNFCVvUXKQj23pEJI5LuqCQD/QTE+uql5+V/nScwZBRs1SIp3795pDp/wY6xj97/zB63n6Z0wyf9
OWFCEZPFk85TatyMFr/uSXnklIWOjCkTtmR5hI6NJG7jolAugSewjuWEsyeYAVVz027Va6JhIe9s
G0huQsayBrZU7dckbJaLuw2yLa6BMcW/OuA6gvsVQy/t0eDXcg7nzxycTOFl7AQDME31WdUwNpBP
/WnD6n2CPQIDAQABo3YwdDAdBgNVHQ4EFgQUjwfbzOjd6U1d8h/FnUknbgVVsa8wRQYDVR0jBD4w
PIAUjwfbzOjd6U1d8h/FnUknbgVVsa+hGaQXMBUxEzARBgNVBAMTCmFhLnVuci5lZHWCCQCnt5Zn
SC/8tTAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQBkyQVyw/QN/yxR6X0YP7I2F05c
5tg2fLcfVRaei6aT0LamyiSioHESyPAwHY8QnC0HRC3lAsS8Gj6F4f4Cr9S0YnUe4lICqVRwjki9
mzsD/ROpDusKraFy72K4WxKvT4S10g67KUZcskG6IKLxhr0vJ5s3TO7pX9C4MMUian2WLFX+ZbaQ
rcc1b0OgqrBXYoBu4CBu8UyI+87Yk92kT6ffKNWTaB19lq/B8bSrzr9PF9LlGOMP1B9ybDXZF6LQ
MoLe2sRYfZHN4YO8atYKriQulEdKJcwie411IeKKNcTderZ024iKboHzbIxRndJ4m65mN+WzrvPC
fCzkE/bHaNBR</ds:X509Certificate>
         </ds:X509Data>
      </ds:KeyInfo>
   </ds:Signature>
   <saml2:Subject>
      <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
         <saml2:SubjectConfirmationData Address="134.197.86.126" InResponseTo="_d6580db7cff14d7bdbd704d600d37f9d" NotOnOrAfter="2012-10-02T18:37:41.984Z" Recipient="https://shib.lynda.com/Shibboleth.sso/SAML2/POST"/>
      </saml2:SubjectConfirmation>
   </saml2:Subject>
   <saml2:Conditions NotBefore="2012-10-02T18:32:41.984Z" NotOnOrAfter="2012-10-02T18:37:41.984Z">
      <saml2:AudienceRestriction>
         <saml2:Audience>https://shib.lynda.com/shibboleth-sp</saml2:Audience>
      </saml2:AudienceRestriction>
   </saml2:Conditions>
   <saml2:AuthnStatement AuthnInstant="2012-10-02T18:32:41.107Z" SessionIndex="f6c1090b6a76c2e2c45bbcb5cc8154ddab62022f038a3e78cf7c04cbdb42cf3c">
      <saml2:SubjectLocality Address="134.197.86.126"/>
      <saml2:AuthnContext>
         <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
      </saml2:AuthnContext>
   </saml2:AuthnStatement>
   <saml2:AttributeStatement>
      <saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
         <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">Hegie</saml2:AttributeValue>
      </saml2:Attribute>
      <saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
         <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">Joshua</saml2:AttributeValue>
      </saml2:Attribute>
      <saml2:Attribute FriendlyName="eduPersonTargetedID" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
         <saml2:AttributeValue>
            <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="https://idp2.unr.edu/idp/shibboleth" SPNameQualifier="https://shib.lynda.com/shibboleth-sp">ifE+PletjKeZsX7BpH/wn2lsprQ=</saml2:NameID>
         </saml2:AttributeValue>
      </saml2:Attribute>
   </saml2:AttributeStatement>
</saml2:Assertion>

They are getting a 500 error.  There is nothing in the logs for it (no suprise since it's a 500). Yes, they are passing eduPersonTargetedID as their security policy precludes the release of EPPN (that I would normally expect).  I have asked them to change this to persistant-id but I doubt that is the issue here regardless.   Can anyone provide some guidance as to how to debug this?  

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121002/fe65ff8c/attachment-0001.html 


More information about the users mailing list