NoPotentialFlow issue with a specific SP with IdP 3.2.1

Mark Cairney Mark.Cairney at ed.ac.uk
Tue Jul 5 05:01:17 EDT 2016


Hi Scott,

Well I'm seeing different behaviour on v2 versus v3 then. I took one of
our v2 IdPs out the pool and cranked the logs up to DEBUG level and it's
doing the following:

09:47:39.306 - DEBUG
[edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOP
rofileHandler:240] - Redirecting user to authentication engine at
https://idp.ed
.ac.uk:443/idp/AuthnEngine
09:47:39.313 - DEBUG
[edu.internet2.middleware.shibboleth.idp.authn.Authenticati
onEngine:209] - Processing incoming request
09:47:39.314 - DEBUG
[edu.internet2.middleware.shibboleth.idp.authn.Authenticati
onEngine:240] - Beginning user authentication process.
09:47:39.314 - DEBUG
[edu.internet2.middleware.shibboleth.idp.authn.Authenticati
onEngine:283] - Filtering configured LoginHandlers:
{urn:oasis:names:tc:SAML:2.0
:ac:classes:unspecified=edu.internet2.middleware.shibboleth.idp.authn.provider.R
emoteUserLoginHandler at 41891394}
09:47:39.314 - DEBUG
[edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:385]
- Forced authentication is required, filtering possible login handlers
accordingly
09:47:39.314 - DEBUG
[edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:406]
- Authentication handlers remaining after forced authentication
requirement filtering:
{urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified=edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserLoginHandler at 41891394}
09:47:39.315 - DEBUG
[edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:464]
- Selecting appropriate login handler from filtered set
{urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified=edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserLoginHandler at 41891394}
09:47:39.315 - DEBUG
[edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:497]
- Authenticating user with login handler of type
edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserLoginHandler
09:47:39.316 - DEBUG
[edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserLoginHandler:66]
- Redirecting to https://idp.ed.ac.uk:443/idp/Authn/RemoteUser
09:47:39.322 - DEBUG
[edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserAuthServlet:73]
- Remote user identified as mcairney returning control back to
authentication engine

So I suppose my question is how do I force Shib 3 to proceed with
Authentication anyway? As we use our own SSO solution with a known
trusted landing page RemoteUser is our only option here.

On 05/07/16 03:12, Cantor, Scott wrote:
> On 7/4/16, 12:07 PM, "users on behalf of Mark Cairney" <users-bounces at shibboleth.net on behalf of Mark.Cairney at ed.ac.uk> wrote:
> 
>> This SP works fine with Shib 2 and has no special configuration
> 
> That SP is requesting ForceAuthn, and use of RemoteUser with either IdP version does not support ForceAuth by default.
> 
> -- Scott
> 
> 

-- 
/****************************

Mark Cairney
ITI Enterprise Services
Information Services
University of Edinburgh

Tel: 0131 650 6565
Email: Mark.Cairney at ed.ac.uk
PGP: 0x435A9621

*******************************/

The University of Edinburgh is a charitable body, registered in
Scotland, with registration number SC005336.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 490 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20160705/2199c6ba/attachment.sig>


More information about the users mailing list