New Shibboleth daemon on new server - user/wayf page just reloads over and over

Johnny Lasker jlasker at educause.edu
Wed Sep 18 18:41:40 EDT 2013


I really appreciate the continued help on this issue.

Today, we tried the config that gets generated with testshib and had good
results. I've attached the config that lets us authenticate against
testshib and returns us back to our site. It also has a commented out
section by the SSO and metadataprovider elements showing what we really
need to use to offer authentication against our pool of Incommon idps.

When we try our values, we get our WAYF page, but clicking on a tile still
just reloads the page.

I checked the transaction log and I see a difference between the two
settings:

Our values
2013-09-18 08:33:19 INFO Shibboleth-TRANSACTION [1]: New session (ID: )
with (applicationId: default) for principal from (IdP: none) at
(ClientAddress: 141.0.10.23) with (NameIdentifier: none) using (Protocol:
urn:oasis:names:tc:SAML:1.1:protocol) from (AssertionID: )
2013-09-18 08:33:19 INFO Shibboleth-TRANSACTION [1]: Cached the following
attributes with session (ID: ) for (applicationId: default) {
2013-09-18 08:33:19 INFO Shibboleth-TRANSACTION [1]: }

Testshib
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: New session (ID:
_ae0939fcefc52f938a6bc198183d65cf) with (applicationId: default) for
principal from (IdP: https://idp.testshib.org/idp/shibboleth) at
(ClientAddress: 63.156.186.130) with (NameIdentifier:
_83d997912b9e3cef0dffdc51fd203180) using (Protocol:
urn:oasis:names:tc:SAML:2.0:protocol) from (AssertionID:
_ce5ed787e4fefa9e3efd11a9cffca14d)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: Cached the following
attributes with session (ID: _ae0939fcefc52f938a6bc198183d65cf) for
(applicationId: default) {
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: 	uid (1 values)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: 	unscoped-affiliation
(1 values)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: 	eppn (1 values)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: 	sn (1 values)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: 	affiliation (1
values)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: 	givenName (1 values)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: 	entitlement (1
values)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: 	cn (1 values)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: 	persistentID (1
values)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: 	telephoneNumber (1
values)
2013-09-18 16:16:06 INFO Shibboleth-TRANSACTION [1]: }




I'm assuming that the lack of a session id is a big factor, would
something like that be affected by our config settings? Because, if we can
change from one source to another (our incommon xml vs. testshib) and have
one generate session ids and the other not, without changing any server
settings, it seems like we are just missing something with our config.

Thank you for your insight.

Johnny Lasker


Johnny Lasker Programmer/Analyst

EDUCAUSE <http://www.educause.edu/>
Uncommon Thinking for the Common Good
282 Century Place, Suite 5000, Louisville, CO 80027
direct: 303.544.5677 | main: 303.449.4430 | educause.edu
<http://www.educause.edu/>





On 9/17/13 5:38 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>On 9/17/13 6:34 PM, "Johnny Lasker" <jlasker at educause.edu> wrote:
>
>>Thank you for your continued help on this.
>>
>>Here is what we get with two different approaches:
>
>This is your code. What does your discovery service require? I assume it's
>a DS protocol service, so using "WAYF" is not going to work.
>
>>Loads the WAYF page, when you click a tile, it reloads the WAYF page
>
>So it's back to at least doing the same thing. So what do the logs say on
>DEBUG? I can't even guess at a cause if I don't have a trace.
>
>There's nothing to go on here, and I have *no* idea how you can get the
>result you're getting. I couldn't make the code do this if I wanted to, I
>cannot find any code path that would result in this behavior. So I'm
>becoming convinced that it isn't my code even running when these requests
>are processed.
>
>-- Scott
>
>
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net

-------------- next part --------------
A non-text attachment was scrubbed...
Name: shibboleth2.xml
Type: application/xml
Size: 4231 bytes
Desc: shibboleth2.xml
Url : http://shibboleth.net/pipermail/users/attachments/20130918/c3529a64/attachment.rdf 


More information about the users mailing list