ACS candidate list empty

IAM David Bantz dabantz at alaska.edu
Sat Oct 11 15:19:14 EDT 2014


I’m seeing a pattern of paired requests, the first of which appears to end
this way:

08:24:04.368 - DEBUG
[org.opensaml.saml2.metadata.support.AttributeConsumingServiceSelector:186]
- Resolving AttributeConsumingService candidates from SPSSODescriptor
08:24:04.368 - DEBUG
[org.opensaml.saml2.metadata.support.AttributeConsumingServiceSelector:141]
- AttributeConsumingService candidate list was empty, can not select service
08:24:04.369 - DEBUG
[edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:832]
- Redirecting to login page [/login.jsp]
08:24:04.369 - DEBUG
[edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:499]
- submodule returned [true]

The second of the pair of requests is typically about 20 or 30 seconds
later from the same IP, and proceeds normally through authentication,
attribute resolution and issuing a SAML assertion.

I’m presuming that means the IdP bailed prior even to authentication on the
first request because it does not know where to send the SAML assertion -
yes?

I’m thrice removed from the end users for this SP unfortunately.  What
would you expect the user experience to be - what will be displayed in
their browser as a result?

Have you seen an SP behave this way or have a suggestion of what it might
be doing?  Or is this down to end user behavior?

Thanks for any insight.


David Bantz
U Alaska
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141011/fdfbf474/attachment.html 


More information about the users mailing list