MCB v. legacy Shibboleth1 profile

Paul Hethmon paul.hethmon at
Fri Apr 11 08:50:28 EDT 2014

On Apr 11, 2014, at 8:31 AM, Paul Hethmon <paul.hethmon at<mailto:paul.hethmon at>> wrote:

My test Shib 2.4 IdP with MCB works fine with all our modern SAML2 SPs, but 3 vendors apparently hard-coded to /profile/Shibboleth/SSO don't. Is this by design? Any workaround? Yes I will try to get the SPs (Symplicity and PeopleAdmin) fixed.

Apr 10, 2014 10:43:02 PM org.apache.catalina.core.StandardWrapperValve invoke
SEVERE: Servlet.service() for servlet AuthenticationEngine threw exception
java.lang.ClassCastException: edu.internet2.middleware.shibboleth.idp.authn.ShibbolethSSOLoginContext cannot be cast to edu.internet2.middleware.shibboleth.idp.authn.Saml2LoginContext
        at edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginHandler.login(

So they are using SAML1?

Ok, I just committed 1.1.3 which uses the base LoginContext instead of the SAML2LoginContext. I believe this should fix the problem.


Paul Hethmon
Chief Software Architect
paul.hethmon at<mailto:paul.hethmon at>

-------------- next part --------------
An HTML attachment was scrubbed...

More information about the users mailing list