Duo IdPv3.3 c14n null principal.

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Wed Dec 28 13:30:27 EST 2016


I am finding that, in the case where an intercept such as the expiring-password condition occurs, the principal is missing from the SubjectCanonicalizationContext, where I believe it was in fact set prior to leaving the authn/Password flow.  It came to my attention because I was getting an NPE from the duo signRequest function in those cases where an intercept had occurred, but did not get the NPE when no intercept occurs between the factors.

My solution is that I am having to have the intercept subflow(s) call the setPrincipal method on the c14n, which is working nicely.  I am just wondering if there is something amiss here.

Thanks for looking at this.

Josh O'Dowd
Software Systems Engineer / Identity Access Management
Central IT, University of Montana

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161228/d8ee3840/attachment.html>


More information about the users mailing list