iOS + Adfs + Shibboleth IDP

Cantor, Scott cantor.2 at osu.edu
Wed Apr 8 22:44:20 EDT 2015


On 4/9/15, 1:51 AM, "Rhian Resnick" <rresnick at fau.edu> wrote:


>
>Here is a trace from the access log and idp-audit.log
>10.19.48.201 - - [08/Apr/2015:21:49:27 -0400] "GET 
>/idp/profile/SAML2/Redirect/SSO?SAMLRequest=jZLditswEIVfxejelm1iOxaOISQUAr
>vdkpRe9E6RRkRgS65GbnbffmWlgZZlQ%2b%2fEaH7Od2Y65OMwse3sL%2bYIv2ZAnxz2G6Jl2p
>xhVVeFTFtRNunq3K7Tc9HUadOcq1KsVa2qmiQ%2fwKG2ZkPKLCfJAXGGg0HPjQ%2bhvKjSfJXm
>7fe8YKuWlVVWt%2bVPkuzDHG24j5UX7ydklCLaTPE5AzlTLSc6Oav0APS0fX4q6RGkdiA8PZ1e
>SLKzBmGZMTvDLEeNzPARkHnBlnwW5DBxS2KzwQmEVhokSb5YJyDyboh3M5DkdRwMsmjE435BkL
>fCDqTvIqi7lT4u4ojgFlDSL6CBk0uFEVSI%2bKYh4bcWgDToQd%2fRW%2fO%2bu%2b3ma2h52H
>%2bzgxZvi%2fqRP8AusiJGwv5UTP0XfjsM9rpzwD3c6el9zp%2f1g4zmBIM9vPr759%2bx3RCY
>jqD%2b37iPHqC4wMgxG7VwFq3ymbAjvSIt83xN8zocQNic9m%2bUh8nLU8RrGcFfrKRT6Hi1Tn
>b0c3n9%2ffMTMPrx9Pt3&RelayState=704a1051-b4f9-4dc7-a1ce-85e217f52652 
>HTTP/1.1" 302 -

That decodes fine, but it contains a RequestedAuthnContext class:

http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/passw
ord

That's proprietary and not something your IdP will know how to fulfill 
unless you teach it to. That will basically fail the request.

>10.19.48.201 - - [08/Apr/2015:21:49:27 -0400] "GET /idp/AuthnEngine 
>HTTP/1.1" 302 -

The process log ought to show it refusing to run any login handlers.

So based on all of that, there's nothing buggy per se, but they're doing 
something you would have to accomodate.

-- Scott

>


More information about the users mailing list