different assertions generated for WEB and ACTIVE clients

Mauro Minella Mauro.Minella at microsoft.com
Tue Jan 15 10:46:44 EST 2013


>> Your logs show clearly to me that your system is authenticating the user with a different username in the two cases, 
>> and I would guess that is causing your resolver configuration to generate different attribute sets in each case, resulting in different data.


My apologies for attaching logs coming from 2 different tests with different users. Here is the assertions I get when I authenticate with michela at shibbdomain.eduteamit.net in either WEB Mail (Internet Explorer) and Outlook 2013 (Active Client). Please note that both of them only ask the same 2 pieces of information (UPN + password), and I need to provide both authentication mechanism, however as far as I understood I did NOT configure a different filter policy or attributes set for WEB and ECP.

============================
WEB AUTHENTICATION (IT WORKS!):
============================
<?xml version="1.0" encoding="UTF-8"?><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://login.microsoftonline.com/login.srf" ID="_50e8442b777c2fac0777fb2dae953107" InResponseTo="_ca19c604-32ee-407b-a7d2-2f7fc7e8ed28" IssueInstant="2013-01-15T15:34:52.849Z" Version="2.0">
   <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://shibbidp.eduteamit.net/idp/shibboleth</saml2:Issuer>
   <saml2p:Status>
      <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
   </saml2p:Status>
   <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_e648805d36ad2535d1a8c62c25bd7286" IssueInstant="2013-01-15T15:34:52.849Z" Version="2.0" xmlns:xs="http://www.w3.org/2001/XMLSchema">
      <saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://shibbidp.eduteamit.net/idp/shibboleth</saml2:Issuer>
      <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
         <ds:SignedInfo>
            <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
            <ds:Reference URI="#_e648805d36ad2535d1a8c62c25bd7286">
               <ds:Transforms>
                  <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                  <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
                     <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>
                  </ds:Transform>
               </ds:Transforms>
               <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
               <ds:DigestValue>LHrX42aDa8PE4TRTCWzgU87HvzI=</ds:DigestValue>
            </ds:Reference>
         </ds:SignedInfo>
         <ds:SignatureValue>fnaKIuZff8yQ7MMrLhtxFis0puucxUfFOfGJKvqTJE5PlLl2gnEbj8PoJJ1D4hYtvMMhW6SXieuNK+KGQYzz/CyVA4CMG5zU5zXpR+TDmSPTCbcxuDoRbTTW4Hx9/ypS3TSKhAcS4Z02rHtcnC6yym1em4HEWb2ogqL200D4qMA3vyHcO1h7IWkjBRokYzo0+taJD+znCSy2KwW/p2rkPNVLFYYZ7q7UlAeDjc12ausUw7DRk4JSrrpe46i2WAvFDnwy3Nne8NasQtSCXyzz9G7UGk7XwrO89oJqj7ahdtAuMnv19/MUitmhPzSbhTz6JXoxMsIDt7b+FKuX0PssXw==</ds:SignatureValue>
         <ds:KeyInfo>
            <ds:X509Data>
               <ds:X509Certificate>(OMISSIS)</ds:X509Certificate>
            </ds:X509Data>
         </ds:KeyInfo>
      </ds:Signature>
      <saml2:Subject>
         <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="https://shibbidp.eduteamit.net/idp/shibboleth" SPNameQualifier="urn:federation:MicrosoftOnline">WcwzuD50xEmCH3xsfbbeEA==</saml2:NameID>
         <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
            <saml2:SubjectConfirmationData Address="94.245.127.21" InResponseTo="_ca19c604-32ee-407b-a7d2-2f7fc7e8ed28" NotOnOrAfter="2013-01-15T15:39:52.849Z" Recipient="https://login.microsoftonline.com/login.srf"/>
         </saml2:SubjectConfirmation>
      </saml2:Subject>
      <saml2:Conditions NotBefore="2013-01-15T15:34:52.849Z" NotOnOrAfter="2013-01-15T15:39:52.849Z">
         <saml2:AudienceRestriction>
            <saml2:Audience>urn:federation:MicrosoftOnline</saml2:Audience>
         </saml2:AudienceRestriction>
      </saml2:Conditions>
      <saml2:AuthnStatement AuthnInstant="2013-01-15T15:34:52.599Z" SessionIndex="91faeb326c400003a8420430e9587203c84ce47b34d7258fd2a195629675396b">
         <saml2:SubjectLocality Address="94.245.127.21"/>
         <saml2:AuthnContext>
            <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
         </saml2:AuthnContext>
      </saml2:AuthnStatement>
      <saml2:AttributeStatement>
         <saml2:Attribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">member at shibbdomain.eduteamit.net</saml2:AttributeValue>
         </saml2:Attribute>
         <saml2:Attribute FriendlyName="UserId" Name="IDPEmail" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">michela at shibbdomain.eduteamit.net</saml2:AttributeValue>
         </saml2:Attribute>
         <saml2:Attribute FriendlyName="eduPersonTargetedID" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <saml2:AttributeValue>
               <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="https://shibbidp.eduteamit.net/idp/shibboleth" SPNameQualifier="urn:federation:MicrosoftOnline">rNIjb0eGUF9akyrG0BsHOoIZE6g=</saml2:NameID>
            </saml2:AttributeValue>
         </saml2:Attribute>
      </saml2:AttributeStatement>
   </saml2:Assertion>
</saml2p:Response>

16:34:53.021 - DEBUG [org.opensaml.ws.message.encoder.BaseMessageEncoder:56] - Successfully encoded message.
16:34:53.021 - INFO [Shibboleth-Audit:989] - 20130115T153453Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_ca19c604-32ee-407b-a7d2-2f7fc7e8ed28|urn:federation:MicrosoftOnline|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://shibbidp.eduteamit.net/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_50e8442b777c2fac0777fb2dae953107|michela@shibbdomain.eduteamit.net|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|transientId,eduPersonScopedAffiliation,UserId,eduPersonTargetedID.old,ImmutableID,eduPersonTargetedID,|WcwzuD50xEmCH3xsfbbeEA==|_e648805d36ad2535d1a8c62c25bd7286,|







==================================
ECP AUTHENTICATION (IT DOES NOT WORK):
==================================
<?xml version="1.0" encoding="UTF-8"?><soap11:Envelope xmlns:soap11="http://schemas.xmlsoap.org/soap/envelope/">
   <soap11:Header>
      <ecp:Response xmlns:ecp="urn:oasis:names:tc:SAML:2.0:profiles:SSO:ecp" AssertionConsumerServiceURL="https://login.microsoftonline.com/login.srf" soap11:actor="http://schemas.xmlsoap.org/soap/actor/next" soap11:mustUnderstand="1"/>
   </soap11:Header>
   <soap11:Body>
      <saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://login.microsoftonline.com/login.srf" ID="_c18f9b112dc1bce238a3a0ca95ba2880" InResponseTo="_b860cd13-a4d7-4527-830d-5cb0bf09f11a" IssueInstant="2013-01-15T15:43:44.642Z" Version="2.0">
         <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://shibbidp.eduteamit.net/idp/shibboleth</saml2:Issuer>
         <saml2p:Status>
            <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
         </saml2p:Status>
         <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_f80abe9848b32b73df90504c6b9fb26a" IssueInstant="2013-01-15T15:43:44.642Z" Version="2.0" xmlns:xs="http://www.w3.org/2001/XMLSchema">
            <saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://shibbidp.eduteamit.net/idp/shibboleth</saml2:Issuer>
            <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
               <ds:SignedInfo>
                  <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                  <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
                  <ds:Reference URI="#_f80abe9848b32b73df90504c6b9fb26a">
                     <ds:Transforms>
                        <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                        <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#">
                           <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/>
                        </ds:Transform>
                     </ds:Transforms>
                     <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
                     <ds:DigestValue>5vkDb7EqSpdvzh0CtgmybDVvzb8=</ds:DigestValue>
                  </ds:Reference>
               </ds:SignedInfo>
               <ds:SignatureValue>JS6mLUJYJDL1nLNODX0tE11cxU7qAmvXYZ+iZ4fZTWxSCeqM3MMBK/D4ay5wRtWI61PXTpIiDBKcprIE2+ygKuD4sQIY707QGswYluj65JwFLowKhTg37JC+QR0SAgak987owUYL846mmkUg2h7Bumxz5cMZdoAa14TAMqag6/pXZy94FahkZLDoEq8/dhFBfTjxgpyBWcG/bwv12AraWWBv8bAWXEl4SqjpjqAgYAbA5MHAYEIjJlAsKV7BVM85n2DnMUrrSdAne/Nqpf/rBRqmBNfIMU4HVEp9JMZygqsYd8yHM73NIeZ52OcS/SOGFBXrh1iGCnThoAmbwD3Dow==</ds:SignatureValue>
               <ds:KeyInfo>
                  <ds:X509Data>
                     <ds:X509Certificate>(OMISSIS)</ds:X509Certificate>
                  </ds:X509Data>
               </ds:KeyInfo>
            </ds:Signature>
            <saml2:Subject>
               <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="https://shibbidp.eduteamit.net/idp/shibboleth">_3eb107c6fa9d1f6b89ae99883d3381d6</saml2:NameID>
               <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                  <saml2:SubjectConfirmationData Address="157.56.254.85" InResponseTo="_b860cd13-a4d7-4527-830d-5cb0bf09f11a" NotOnOrAfter="2013-01-15T15:48:44.642Z" Recipient="https://login.microsoftonline.com/login.srf"/>
               </saml2:SubjectConfirmation>
            </saml2:Subject>
            <saml2:Conditions NotBefore="2013-01-15T15:43:44.642Z" NotOnOrAfter="2013-01-15T15:48:44.642Z">
               <saml2:AudienceRestriction>
                  <saml2:Audience>urn:federation:MicrosoftOnline</saml2:Audience>
               </saml2:AudienceRestriction>
            </saml2:Conditions>
            <saml2:AuthnStatement AuthnInstant="2013-01-15T15:43:44.642Z">
               <saml2:SubjectLocality Address="157.56.254.85"/>
               <saml2:AuthnContext>
                  <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef>
               </saml2:AuthnContext>
            </saml2:AuthnStatement>
            <saml2:AttributeStatement>
               <saml2:Attribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
                  <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">member at shibbdomain.eduteamit.net</saml2:AttributeValue>
               </saml2:Attribute>
            </saml2:AttributeStatement>
         </saml2:Assertion>
      </saml2p:Response>
   </soap11:Body>
</soap11:Envelope>

16:43:44.815 - DEBUG [org.opensaml.ws.message.encoder.BaseMessageEncoder:56] - Successfully encoded message.
16:43:44.831 - INFO [Shibboleth-Audit:989] - 20130115T154344Z|urn:oasis:names:tc:SAML:2.0:bindings:SOAP|_b860cd13-a4d7-4527-830d-5cb0bf09f11a|urn:federation:MicrosoftOnline|urn:oasis:names:tc:SAML:2.0:profiles:SSO:ecp|https://shibbidp.eduteamit.net/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:SOAP|_c18f9b112dc1bce238a3a0ca95ba2880|michela||transientId,eduPersonScopedAffiliation,|_3eb107c6fa9d1f6b89ae99883d3381d6|_f80abe9848b32b73df90504c6b9fb26a,|


More information about the users mailing list