open ports / version mismatch

Cantor, Scott cantor.2 at osu.edu
Tue Jun 11 21:47:06 EDT 2013


On 6/11/13 9:25 PM, "Nate Klingenstein" <ndk at internet2.edu> wrote:
>
>I guess if I had to grasp at a straw, I'd see if the SP's that the IdP is
>working with successfully are including a desired authentication method
>of urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport with
>their requests, as Eric alluded to, while your SP is not specifying a
>desired authentication method in its requests, and the IdP has both
>ph:RemoteUser and ph:UsernamePassword uncommented and using the default
>configuration.
>
>If my straw is the correct one, the best fix in this case would probably
>be for the IdP to comment out the RemoteUser login handler.

Yes. Emphasis on the fact that this isn't your issue, you shouldn't change
anything your SP is doing, and their end is not configured correctly.
There is no way anything you send it should result in an AuthnFailed
message caused by a missing REMOTE_USER value. That is a misconfiguration,
by definition.

-- Scott




More information about the users mailing list