Salesforce error when authing against Shibboleth

Ben Branch BBranch at uco.edu
Fri Aug 8 17:17:28 EDT 2014


All,

It appears that the problem I have been experiencing is an issue with attribute releasing.  I thought I had this configured properly, but it appears I do not.  I can't get the aacli.sh script to work ( I get java errors about a classpath) to test this.  I feel like I'm really missing something obvious here and I have no idea what it is.  I logged into testshib.org and I don't see any attributes come across.  In an attempt to try and release attributes to sp.testshib.org, I configured an attribute filter to release the email attribute to that specific SP.

Does the SSL cert that is loaded into Tomcat need to be the same one that is used by the IDP itself (the idp.crt used for metadata needs to be the same cert used for SSL)?  Currently, I have a wildcard certificate loaded on this server, and I do not have the idp.jks loaded on any other ports. Do I just need to create a new port connector in my Tomcat configuration and load idp.jks onto that port?

Testshib.org SP Log: http://pastebin.com/Kn7pyttK


Ben Branch
UNIX/Linux Administrator
University of Central Oklahoma
ITIL Foundation v3, Network+, RHCSA

100 N. University Drive, Box 122
Edmond, OK 73034
D: 405.974.2649 | M: 405.550.6804 | bbranch at uco.edu | www.uco.edu

"I am wiser than this man, for neither of us appears to know anything great and good; but he fancies he knows something, although he knows nothing; whereas I, as I do not know anything, so I do not fancy I do. In this trifling particular, then, I appear to be wiser than he, because I do not fancy I know what I do not know."  - Socrates

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Peter Schober
Sent: Thursday, August 07, 2014 4:37 PM
To: users at shibboleth.net
Subject: Re: Salesforce error when authing against Shibboleth

* Ben Branch <BBranch at uco.edu> [2014-08-07 21:05]:
> Anyone mind taking a peek and see if they can see anything that is
> wrong with this?  What I am including is the complete authentication
> session for 1 user.

You can't really expect to find this error in the IDP's logs, as the IDP signs with withever it's configured to sign and sends you off, esp. since you don't even have debugging of protocol messages enabled, which would show the key used (not that that would help anyone here, as we lack something to compare it against).

Does this IDP work with other SPs and is signature validation not an issue there? I'm assuming it is.

Did you try encrypting the response to the vendor instead, just to see whether that changes anything?

> On a side note, I have opened a ticket with our
> vendor (Remedy Force).   Just a note, if you are using Remedy Force
> and attempt to open a ticket with SalesForce and you do not have
> premier support with Salesforce, they will not assist you in
> troubleshooting your SSO issues (I found this out this morning).

While the vendor's refusal to do its part is certainly unhelpful, from this doesn't follow that the Shibboleth community is in a position to diagnose the failed signature validation at that SP.
-peter
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
**Bronze+Blue=Green** The University of Central Oklahoma is Bronze, Blue, and Green! Please print this e-mail only if absolutely necessary!

**CONFIDENTIALITY** -This e-mail (including any attachments) may contain confidential, proprietary and privileged information. Any unauthorized disclosure or use of this information is prohibited.


More information about the users mailing list