When using IDP 2.4.4 and MCB 1.2.5 we are seeing AuthnFailed message after authenticating to one sp then switching to a new tab with an sp that forces reauth

Ewing, Bill BEwing at utsystem.edu
Tue Jun 30 15:50:52 EDT 2015


Ever since we've started using the IDP 2.4.4 and MCB 1.2.5 in preparation for rolling out 2factor we have our users seeing the AuthnFailed message when after authenticating to one sp previously opens a new browser tab and visits an sp that is set to force re-authentication. One of our other schools with a similar setup disabled their setup for previous sessions to get around this issue. We were wondering if this was a known issue for this scenario or are we missing something with our config on the sp or idp possibly? I'll paste the idp log snippet below

Idp log snip.
14:05:51.971 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:680] - Force reauth = [true]
14:05:51.971 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:684] - Found [0] allowable contexts to choose from.
14:05:51.971 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:712] - Relying party did not request a context, using potential context list for the user.
14:05:51.971 - WARN [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:732] - Unable to satisfy requested authentication context of [[]]. Returning SAML error to SP.
14:05:51.971 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:144] - Returning control to authentication engine
14:05:51.971 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:209] - Processing incoming request
14:05:51.971 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:514] - Completing user authentication process
14:05:51.971 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:585] - Validating authentication was performed successfully
14:05:51.971 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:605] - Exception returned from login handler for authentication method urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport:
edu.internet2.middleware.shibboleth.idp.authn.AuthenticationException: Unable to satisfy requested authentication context.



Login error below.
SAML response contained an error.

Error from identity provider:

Status: urn:oasis:names:tc:SAML:2.0:status:Responder

Sub-Status: urn:oasis:names:tc:SAML:2.0:status:AuthnFailed

William Ewing, Senior Information Security Analyst
CISSP, MCSE, MCITP-EA, CCNA/CCDA
UT System - Office of Information Security & Compliance
210 West 6th Street
Austin, Texas 78701-3035
Phone: (512)499-4575
email: bewing at utsystem.edu<mailto:bewing at utsystem.edu>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150630/7c6312b8/attachment-0001.html>


More information about the users mailing list