SP stopped working after IDP upgraded to 3.1.1

Hong Ye hy93 at cornell.edu
Tue Apr 7 10:45:31 EDT 2015


Hi,

I upgraded our test IDP to 3.1.1. During testings, I found one SP stopped working while others worked fine. No error or warning in idp-process.log. There is info level message showing "None of the potential authentication flows can satisfy the request”. Is this something I can fix in IDP configuration or it has to be fixed in SP? This SP worked fine before the upgrade.

<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"

                    ID="s2318e95b21f623e2ab7a5e276c4b8cf8e0b03f5dc"
                    Version="2.0"
                    IssueInstant="2015-04-07T14:04:18Z"
                    Destination="https://shibidp-test.cit.cornell.edu/idp/profile/SAML2/Redirect/SSO"
                    ForceAuthn="false"
                    IsPassive="false"
                    ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
                    AssertionConsumerServiceURL="https://login-ma-sso.onbmc.com:443/atriumsso/Consumer/metaAlias/cornell-dev/sp"
                    >
    <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">sp</saml:Issuer>
    <samlp:NameIDPolicy xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                        Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
                        AllowCreate="true"
                        />
    <samlp:RequestedAuthnContext xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                                 Comparison="minimum"
                                 >
        <saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml:AuthnContextClassRef>
    </samlp:RequestedAuthnContext>
</samlp:AuthnRequest>


<saml2p:Response Destination="https://login-ma-sso.onbmc.com:443/atriumsso/Consumer/metaAlias/cornell-dev/sp"
                 ID="_032a389124ff07af050fe4a658eebba2"
                 InResponseTo="s265fdd20a8b4f39c82aab327e63a7e91be0772700"
                 IssueInstant="2015-04-07T14:16:28.214Z"
                 Version="2.0"
                 xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
                 >
    <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">https://shibidp-test.cit.cornell.edu/idp/shibboleth</saml2:Issuer>
    <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:SignedInfo>
            <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
            <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
            <ds:Reference URI="#_032a389124ff07af050fe4a658eebba2">
                <ds:Transforms>
                    <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
                    <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                </ds:Transforms>
                <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
                <ds:DigestValue>hx3Z5VkioBUDFqq/hqzV2ugFLhr3qNchrfkf5M57q4k=</ds:DigestValue>
            </ds:Reference>
        </ds:SignedInfo>
        <ds:SignatureValue>
NB/DVSxDUSm/tRn6cgp9fapwQzlpv9Lw07m3Y1JLHI2L2gG6Ja65F/4PsFS4CXum6bcBA8cJOs+d
3+PDxnKUs1N5YGfDMP/w3vdY25MDXiFjwuvJX+J612wD8yt2gBcMfquPIjSlif6+GbjU5alrbdQd
z6JWcmt+W5UeHKuLKpjoWJIBKDr9+ThaaLPHlVQtVn7YA0EpF9Q8GM5MPVvlbf2YT2uXcfSCckT/
rggZiVl74omiVjwnGy5i6ECoIk459Ph9dQTwBuk1ihoSDcEKg/vJYHNh8IZ9UdYnGTGXoFycu2P2
pXJlZn4u2mVpdOeyCbsWc8Spc85KTx7eLEV/Iw==
</ds:SignatureValue>
        <ds:KeyInfo>
            <ds:X509Data>
                <ds:X509Certificate>MIIDXDCCAkSgAwIBAgIVAMKCR8IGXIOzO/yLt6e4sd7OMLgEMA0GCSqGSIb3DQEBBQUAMCcxJTAj
BgNVBAMTHHNoaWJpZHAtdGVzdC5jaXQuY29ybmVsbC5lZHUwHhcNMTIwNjA3MTg0NjIyWhcNMzIw
NjA3MTg0NjIyWjAnMSUwIwYDVQQDExxzaGliaWRwLXRlc3QuY2l0LmNvcm5lbGwuZWR1MIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkhlf9EP399mqnBtGmPG9Vqu79Af2NZhhsT+LTMA1
uhPZYv4RX/E4VD+Iqce/EUP1ndPkGEwBnhrRT2ZegDpCmgo+EcED8cAh9AbwFTTitmBjxvErtJnS
0ZBfMCLDcgOV1zM6bT5fF9SAIm0ZVSaeyQbNDwVDdwsBQHjAdg5vLd5VeYH9MI6enzdgBtPNSrEt
3qZtCWl7ev8YQlWF3vZ+EoyDrWPZSOWzgR31QBs7mz13ABSveIri68FgNth9ylgFS7VNUlAp6xx6
BRnMgL1QzVMZ5F4PbSRDp3UBoS6PMHd+WFenJWPPh6ShMyrInrJ4QAPfKC77tJW+GUXl4T4DqQID
AQABo38wfTBcBgNVHREEVTBTghxzaGliaWRwLXRlc3QuY2l0LmNvcm5lbGwuZWR1hjNodHRwczov
L3NoaWJpZHAtdGVzdC5jaXQuY29ybmVsbC5lZHUvaWRwL3NoaWJib2xldGgwHQYDVR0OBBYEFF9R
ADnmBsO50hD8T+MUFqIgWAOxMA0GCSqGSIb3DQEBBQUAA4IBAQBqYpfdK4XAYE56sYmq/vUKOSBc
bO2Uy3R7oTGrDKxrZI7xC1jchaaTW6BXtg6wzTSn8Jo2M0gvQrWyxZgQDrXGaL2TaPf5WjOWt/Ss
uJ+IShofS6ZWLkPCnrR0Ag9PwU58szw2jjUE4eJyv/dLDzhDHJ0EGastgSzRh1r3v2w8BYz1RHvj
wESPB2HTgV1iuHwaIjaJxN39XyS6ZQzBj6sZ6Lem1R39zXmEvtVfCk9qgSKnbYulrrkIBzxllB34
TUTKFs+Nz1j/sg2gj6Q5u9uW6mSm66mqn2E53r2CNHPTzWGwom5Mi9Z/DtOb2L/5jjxhFvCKxnEb
IWm7XIe8qtqo</ds:X509Certificate>
            </ds:X509Data>
        </ds:KeyInfo>
    </ds:Signature>
    <saml2p:Status>
        <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Requester">
            <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:NoAuthnContext" />
        </saml2p:StatusCode>
        <saml2p:StatusMessage>authn</saml2p:StatusMessage>
    </saml2p:Status>
</saml2p:Response>


Thanks,
Hong
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150407/d2743979/attachment-0001.html 


More information about the users mailing list