Error Message with IdP "LoginContext key cookie was not present in request"
Patrick Rynhart
P.Rynhart at massey.ac.nz
Sat Jan 4 03:56:28 EST 2014
Hi Kevin,
Thank you for your replies.
>On 4/01/2014 12:12 p.m., Kevin Foote wrote:
>
>The “LoginContext key cookie.. “ messages have nothing to do with the
>Lynda requests / post process.
>Are you sure you are sending all the attributes you need to from your
>prod IdP?
AFAIK, yes. (The login has been working successfully previously for
several months.)
>What does the UI (browser) error report show.. ?
Firstly, I thought that the "LoginContext key cookie" message was the
cause (and the message displayed in the UI a fallback / secondary error
message, i.e. not necessarily the "cause").
To answer your question, the message displayed in the UI is:
opensaml::FatalProfileException
The system encountered an error at Sat Jan 04 00:28:03 2014
To report this problem, please contact the site administrator at
mflynn at lynda.com.
Please include the following message in any email:
opensaml::FatalProfileException at
(https://shib.lynda.com/Shibboleth.sso/SAML2/POST)
Message was signed, but signature could not be verified.
This suggests that it's a metadata issue. If so, the problem now is
that I haven't changed the metadata at my end (and I'm successfully
federated with other external SPs which are still working.) I've also
been in touch with Lynda.com technical support who have said that my
metadata hasn't been changed at their end.
Is there any way to get any more information to 'prove' which end has
misbehaving ? Or is "signature could not be verified" as good as it gets ?
> actually your attribute stack does look a little different on the two releases..
>
>
> PROD:
>
> - INFO [Shibboleth-Audit:989] - 20140103T200048Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_ce588315b22a1c4396dedf130250871d|https://shib.lynda.com/shibboleth-sp|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://idp.massey.ac.nz/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_e6ca73607c0983f37ee0a94217d44df3|prynhart|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|eduPersonAffiliation,eduPersonPrincipalName,eduPersonPrimaryAffiliation,transientId,surname,eduPersonScopedAffiliation,givenName,eduPersonTargetedID,email,displayName,|_f378d3878bb5297463f6fb02dc1f4006||
>
> TEST:
>
> - INFO [Shibboleth-Audit:1028] - 20140103T202156Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_c0f11eb204560633df556b738e3a59ef|https://shib.lynda.com/shibboleth-sp|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://idp-test.massey.ac.nz/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_05daf5afbee2f1dfe4fc42257dd75ce5|prynhart|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|eduPersonAffiliation,eduPersonPrincipalName,transientId,surname,givenName,displayName,lynda.com_mail,|_1ff77810e126b236f4eacd0b73aaa226||
>
Well spotted. I have reconciled differences between my respective Prod
& Test attribute-resolver.xml & attribute-filter.xml filter files. The
updated traces are available at:
Prod:
http://www.massey.ac.nz/~prynhart/downloads/LyndaCom_Login_Error_20140104_v2.txt
Test:
http://www.massey.ac.nz/~prynhart/downloads/LyndaCom_Login_Error_20140104_via_TestIdP_v2.txt
Prod has the uApprove module while Test doesn't (hence the difference in
# of lines).
> thanks
> kevin.foote
>
Regards,
Patrick
> On Jan 3, 2014, at 2:33 PM, Patrick Rynhart <P.Rynhart at massey.ac.nz> wrote:
>
>> Hi,
>>
>> We have two Shibboleth IdPs (a production and test instance) which is
>> federated with the same SP (Lynda.com). Until recently, both have been
>> functioning correctly. However, within the last few days, our
>> production IdP instance fails when attempting to log into this SP.
>> After turning up the log level to DEBUG, the error message "LoginContext
>> key cookie was not present in request" is found in the logs (just after
>> the POST). Other SPs that our Prod IdP is federated with aren't
>> affected. We've also tried different browser sessions and user
>> combinations.
>>
>> I provide DEBUG logs during a login attempt for both the Production (not
>> working with Lynda.com) IdP and the Test (working with Lynda.com) IdPs.
>> The version of Shibboleth used in Prod is 2.3 while that in Test is
>> 2.4 - but they are configured similarly. I am posting both versions for
>> comparison because the bulk of the logs are similar and I can't spot any
>> (obvious) differences as to one should fail while the other succeed.
>>
>> Production IdP (idp.massey.ac.nz) - Not Working with Lynda.com:
>> http://www.massey.ac.nz/~prynhart/downloads/LyndaCom_Login_Error_20140104.txt
>>
>> Test IdP (idp-test.massey.ac.nz) - Working With Lynda.com:
>> http://www.massey.ac.nz/~prynhart/downloads/LyndaCom_Login_Error_20140104_via_TestIdP.txt
>>
>> If someone could please help me troubleshoot this issue it would be most
>> appreciated. The reason for the "break" isn't known - in particular
>> there haven't been any (known) configuration changes at either end.
>>
>> With Thanks,
>>
>> Patrick
>>
>> --
>> Patrick Rynhart
>> Systems Engineer
>> Infrastructure Support Section
>> Information Technology Services
>> Massey University
>> Palmerston North
>> New Zealand
>>
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
More information about the users
mailing list