PasswordProtectedTransport Authentication with MCB

David Langenberg davel at uchicago.edu
Tue Jun 23 20:48:42 EDT 2015


Do you have a <Context> defined in your multi-context-broker.xml file for
PasswordProtectedTransport?

Dave

On Tue, Jun 23, 2015 at 6:45 PM, IAM David Bantz <dabantz at alaska.edu> wrote:

> A vendor (afford.com's TMS) is sending a SAML request my IdP 2.x with MCB
> cannot handle.
> Here's the initial sign of trouble in my IdP process log:
>
> 12:37:43.141 - WARN
> [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:400]
> -
>                         Error decoding authentication request message org.opensaml.ws.message.decoder.MessageDecodingException:
>
>                         No SAMLRequest or SAMLResponse query path
> parameter, invalid SAML 2 HTTP Redirect message
>
> (Is there a logging setting that will display the exact unencoded SAML
> request in the process log?)
>
> According to the vendor, the IdP needs to support
> PasswordProtectedTransport Authentication in relying-party.xml, but as we
> have MCB installed, I think there's more to it.  Here's what the MCB adds
> to the logs for this request; although the user's input did authenticate
> via LDAP directory (and attributes were resolved) this does not satisfy the
> request:
>
> 12:38:40.676 - DEBUG
> [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:227]
> -
>                         User authenticated with method [password]
>
> 12:38:40.676 - DEBUG
> [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:257]
> -
>                         Used context listed in valid contexts = [false]
>
> 12:38:40.676 - DEBUG
> [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:261]
> -
>                         User [uaguest_bbouchard1] used a context NOT on
> the potential context list. They must re-authenticate with a valid context.
>
> 12:38:40.676 - DEBUG
> [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:544]
> -
>                         Found [0] allowable contexts to choose from.
>
> 12:38:40.677 - WARN
> [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:573]
> -
>                         Unable to satisfy requested authentication context
> of [[urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport]].
> Returning SAML error to SP.
>
> with the result:
>
> 12:38:40.677 - DEBUG
> [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:156]
> - Authentication result = [false]
>
> What do I need to change to support the vendor's SAML request for
> PasswordProtectedTransport authentication method?
>
> David Bantz
> U Alaska IAM
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
David Langenberg
Identity & Access Management Architect
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150623/666c02fd/attachment-0001.html>


More information about the users mailing list