Office 365 -> ADFS ->Shibboleth iOS problems?

Eric Kool-Brown kool at uw.edu
Wed Aug 17 17:36:00 EDT 2016


Hi Patrick,

I've also opened a case with Microsoft about this (SR # 116080914525742) and was told to install the Azure Authenticator app. That seems to fix the problem for me but others are still seeing this. It is being discussed on the offic365 at ucdavis.edu<mailto:offic365 at ucdavis.edu> listserv.

I've asked the MS PSE for more information about what's going on, specifically what the Authenticator app is doing. I have not heard back on that.

Also, one of our IAM team members, Michael Brogan, attempted to troubleshoot by setting up a proxy server. He only saw one difference between the two requests (from the old OneDrive for Business app that works without Authenticator and the new OneDrive app again without Authenticator) and the only difference was the presence of a new, non-standard, header requesting MS-PKAP auth. That is a proprietary cert-based device registration/authentication protocol. I presume the Authenticator app is leveraging this new protocol.

We are running ADFS 2.0 so I would be surprised if it recognized the new MS-PKAP header and acted on it, but perhaps this was added via an update.

Clearly testing with ADFS using Shib is not part of the MS testing matrix.

    Eric Kool-Brown
    Software Engineer
    University of Washington - IT Identity and Access Management


From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Patrick Le
Sent: Wednesday, August 17, 2016 12:00 PM
To: users at shibboleth.net
Subject: Office 365 -> ADFS ->Shibboleth iOS problems?

Does anyone Federate their office 365 environment with ADFS but treat ADFS as a relying party to Shibboleth? If so, have you experienced any issues with IOS app authentication in the last week with Office apps (Word, Excel, PowerPoint, etc.).

We've been seeing some issues since Thursday when Microsoft released updates to their IOS apps. When Shib gets the auth request from ADFS, Shib throws an error:

14:24:29.750 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:400] - Error decoding authentication request message
org.opensaml.ws.message.decoder.MessageDecodingException: No SAMLRequest or SAMLResponse query path parameter, invalid SAML 2 HTTP Redirect message
        at org.opensaml.saml2.binding.decoding.HTTPRedirectDeflateDecoder.doDecode(HTTPRedirectDeflateDecoder.java:98) ~[opensaml-2.6.0.jar:na]
        at org.opensaml.ws.message.decoder.BaseMessageDecoder.decode(BaseMessageDecoder.java:79) ~[openws-1.5.0.jar:na]
        at org.opensaml.saml2.binding.decoding.BaseSAML2MessageDecoder.decode(BaseSAML2MessageDecoder.java:70) ~[opensaml-2.6.0.jar:na]


We've spent the last three days with Microsoft support and have not gotten anywhere with them. We tell them we're missing the query path from ADFS to return the auth request to but they keep telling auth the saml request is the same between both old and new versions. Funny thing is, when we try a device with the previous app versions prior to Thursday, authentication works fine. Yet they still insist that nothing within the authentication stack was changed on the app side even though there's clearly a difference in user experience.

Just seeing if anyone with a similar setup is seeing the same things and if you discovered a workaround.

Thanks

Patrick
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160817/8ec91686/attachment-0001.html>


More information about the users mailing list