ACS candidate list empty
IAM David Bantz
dabantz at alaska.edu
Sat Oct 11 15:19:14 EDT 2014
I’m seeing a pattern of paired requests, the first of which appears to end
this way:
08:24:04.368 - DEBUG
[org.opensaml.saml2.metadata.support.AttributeConsumingServiceSelector:186]
- Resolving AttributeConsumingService candidates from SPSSODescriptor
08:24:04.368 - DEBUG
[org.opensaml.saml2.metadata.support.AttributeConsumingServiceSelector:141]
- AttributeConsumingService candidate list was empty, can not select service
08:24:04.369 - DEBUG
[edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:832]
- Redirecting to login page [/login.jsp]
08:24:04.369 - DEBUG
[edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:499]
- submodule returned [true]
The second of the pair of requests is typically about 20 or 30 seconds
later from the same IP, and proceeds normally through authentication,
attribute resolution and issuing a SAML assertion.
I’m presuming that means the IdP bailed prior even to authentication on the
first request because it does not know where to send the SAML assertion -
yes?
I’m thrice removed from the end users for this SP unfortunately. What
would you expect the user experience to be - what will be displayed in
their browser as a result?
Have you seen an SP behave this way or have a suggestion of what it might
be doing? Or is this down to end user behavior?
Thanks for any insight.
David Bantz
U Alaska
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141011/fdfbf474/attachment.html
More information about the users
mailing list