Shibboleth IDP 3 as CAS Server

Jesse Martinich martinicj at sou.edu
Fri Jun 12 19:26:45 EDT 2015


It's Friday afternoon, so hopefully you're all relaxing. I am still getting
the following error in my browser:

Authorization Required

This server could not verify that you are authorized to access the document
requested. Either you supplied the wrong credentials (e.g., bad password),
or your browser doesn't understand how to supply the credentials required.

Apache/2.2.15 (CentOS) Server at cas.sou.edu Port 443

In the debug logs on the client I see attributes come over. It looks like
the same ones are sent twice:

[Fri Jun 12 16:11:50 2015] [debug] mod_auth_cas.c(539): [client
140.211.91.96] CAS Service 'https%3a%2f%2fcas.sou.edu%2fsecure', referer:
https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1

[Fri Jun 12 16:11:50 2015] [debug] mod_auth_cas.c(1674): [client
140.211.91.96] Validation response: <?xml version="1.0"
encoding="UTF-8"?>\n<soap11:Envelope xmlns:soap11="
http://schemas.xmlsoap.org/soap/envelope/"><soap11:Body><saml1p:Response
MajorVersion="1" MinorVersion="1"
xmlns:saml1p="urn:oasis:names:tc:SAML:1.0:protocol"><saml1p:Status><saml1p:StatusCode
Value="saml1p:Success"/></saml1p:Status><saml1:Assertion
AssertionID="_d0a6df8c17fc994bded713a9e7f3740f"
IssueInstant="2015-06-12T23:11:50.967Z" Issuer="
https://shib.sou.edu/idp/shibboleth" MajorVersion="1" MinorVersion="1"
xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"><saml1:Conditions
NotBefore="2015-06-12T23:11:50.967Z"
NotOnOrAfter="2015-06-12T23:12:50.967Z"><saml1:AudienceRestrictionCondition><saml1:Audience>
https://cas.sou.edu/secure</saml1:Audience></saml1:AudienceRestrictionCondition></saml1:Conditions><saml1:AuthenticationStatement
AuthenticationInstant="2015-06-12T23:11:50.967Z"
AuthenticationMethod="authn/Password"><saml1:Subject><saml1:NameIdentifier>martinicj</saml1:NameIdentifier><saml1:SubjectConfirmation><saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:artifact</saml1:ConfirmationMethod></saml1:SubjectConfirmation></saml1:Subject></saml1:AuthenticationStatement><saml1:AttributeStatement><saml1:Subject><saml1:NameIdentifier>martinicj</saml1:NameIdentifier><saml1:SubjectConfirmation><saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:artifact</saml1:ConfirmationMethod></saml1:SubjectConfirmation></saml1:Subject><saml1:Attribute
AttributeName="eduPersonPrimaryAffiliation" AttributeNamespace="
http://www.ja-sig.org/products/cas/"><saml1:AttributeValue xmlns:xsd="
http://www.w3.org/2001/XMLSchema" xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xsd:string">staff</saml1:AttributeValue></saml1:Attribute><saml1:Attribute
AttributeName="transientId" AttributeNamespace="
http://www.ja-sig.org/products/cas/"><saml1:AttributeValue xmlns:xsd="
http://www.w3.org/2001/XMLSchema" xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xsd:string">_b8e240b3acbc0c93f620214de705e4d7</saml1:AttributeValue></saml1:Attribute><saml1:Attribute
AttributeName="mail"
AttributeNamespace="http://www.ja-sig.org/products/cas/"><saml1:AttributeValue
xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">
martinicj at sou.edu</saml1:AttributeValue></saml1:Attribute><saml1:Attribute
AttributeName="eduPersonPrincipalName" AttributeNamespace="
http://www.ja-sig.org/products/cas/"><saml1:AttributeValue xmlns:xsd="
http://www.w3.org/2001/XMLSchema" xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xsd:string">martinicj</saml1:AttributeValue></saml1:Attribute></saml1:AttributeStatement></saml1:Assertion></saml1p:Response></soap11:Body></soap11:Envelope>,
referer:
https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1

[Fri Jun 12 16:11:50 2015] [debug] mod_auth_cas.c(1293): [client
140.211.91.96] entering isValidCASTicket(), referer:
https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1

[Fri Jun 12 16:11:50 2015] [debug] mod_auth_cas.c(1299): [client
140.211.91.96] MOD_AUTH_CAS: response = <?xml version="1.0"
encoding="UTF-8"?>\n<soap11:Envelope xmlns:soap11="
http://schemas.xmlsoap.org/soap/envelope/"><soap11:Body><saml1p:Response
MajorVersion="1" MinorVersion="1"
xmlns:saml1p="urn:oasis:names:tc:SAML:1.0:protocol"><saml1p:Status><saml1p:StatusCode
Value="saml1p:Success"/></saml1p:Status><saml1:Assertion
AssertionID="_d0a6df8c17fc994bded713a9e7f3740f"
IssueInstant="2015-06-12T23:11:50.967Z" Issuer="
https://shib.sou.edu/idp/shibboleth" MajorVersion="1" MinorVersion="1"
xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"><saml1:Conditions
NotBefore="2015-06-12T23:11:50.967Z"
NotOnOrAfter="2015-06-12T23:12:50.967Z"><saml1:AudienceRestrictionCondition><saml1:Audience>
https://cas.sou.edu/secure</saml1:Audience></saml1:AudienceRestrictionCondition></saml1:Conditions><saml1:AuthenticationStatement
AuthenticationInstant="2015-06-12T23:11:50.967Z"
AuthenticationMethod="authn/Password"><saml1:Subject><saml1:NameIdentifier>martinicj</saml1:NameIdentifier><saml1:SubjectConfirmation><saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:artifact</saml1:ConfirmationMethod></saml1:SubjectConfirmation></saml1:Subject></saml1:AuthenticationStatement><saml1:AttributeStatement><saml1:Subject><saml1:NameIdentifier>martinicj</saml1:NameIdentifier><saml1:SubjectConfirmation><saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:artifact</saml1:ConfirmationMethod></saml1:SubjectConfirmation></saml1:Subject><saml1:Attribute
AttributeName="eduPersonPrimaryAffiliation" AttributeNamespace="
http://www.ja-sig.org/products/cas/"><saml1:AttributeValue xmlns:xsd="
http://www.w3.org/2001/XMLSchema" xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xsd:string">staff</saml1:AttributeValue></saml1:Attribute><saml1:Attribute
AttributeName="transientId" AttributeNamespace="
http://www.ja-sig.org/products/cas/"><saml1:AttributeValue xmlns:xsd="
http://www.w3.org/2001/XMLSchema" xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xsd:string">_b8e240b3acbc0c93f620214de705e4d7</saml1:AttributeValue></saml1:Attribute><saml1:Attribute
AttributeName="mail"
AttributeNamespace="http://www.ja-sig.org/products/cas/"><saml1:AttributeValue
xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance" xsi:type="xsd:string">
martinicj at sou.edu</saml1:AttributeValue></saml1:Attribute><saml1:Attribute
AttributeName="eduPersonPrincipalName" AttributeNamespace="
http://www.ja-sig.org/products/cas/"><saml1:AttributeValue xmlns:xsd="
http://www.w3.org/2001/XMLSchema" xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance"
xsi:type="xsd:string">martinicj</saml1:AttributeValue></saml1:Attribute></saml1:AttributeStatement></saml1:Assertion></saml1p:Response></soap11:Body></soap11:Envelope>,
referer:
https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1


I'm stumped. I don't know if my server is still doing something wrong, or
if it's just a client-side issue at this point.

Thanks, and have a good weekend all.

Jesse




*Jesse Martinich*
Systems Administrator
Southern Oregon University | 1250 Siskiyou Blvd | Ashland OR  97520
541-552-8424


On Fri, Jun 12, 2015 at 10:46 AM, Jesse Martinich <martinicj at sou.edu> wrote:

> Thank you. You saved me from going down that rabbit hole.
>
> After enabling the MemcachedStorageService, I now have attributes flowing
> to the CAS client.
>
> I am still getting "Authorization Required", but I am guessing that is a
> client-side configuration issue. I will update after I have dug in some
> more.
>
> Thanks All!
>
> Jesse
>
>
> *Jesse Martinich*
> Systems Administrator
> Southern Oregon University | 1250 Siskiyou Blvd | Ashland OR  97520
> 541-552-8424
>
>
> On Fri, Jun 12, 2015 at 10:04 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
>> On 6/12/15, 12:47 PM, "users on behalf of Jesse Martinich" <
>> users-bounces at shibboleth.net on behalf of martinicj at sou.edu> wrote:
>>
>> >Please excuse my ignorance. I think Walter may have alluded to this
>> yesterday... Might I need to setup back channel support for SOAP endpoints?
>>
>> Not if your validation call is using 443.
>>
>> In SAML terms, using endpoints protected by commercial certificates and
>> having to implement trust on that basis is a mess. I would imagine that's
>> less true of a CAS scenario where the number of such trusts is one. But I
>> also think there's no reason you couldn't use a back channel port with a
>> self-signed cert either, but you likely wouldn't bother unless you were
>> also doing it for SAML.
>>
>> The IdP doesn't really pay attention to the port when it comes to the
>> profile endpoints it runs, so anything on 443 is basically available on
>> 8443 if it's configured to support that.
>>
>> -- Scott
>>
>> --
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150612/bf12cb56/attachment-0001.html>


More information about the users mailing list