Educause SP login

Michael Dahlberg olgamirth at gmail.com
Mon Mar 14 17:27:18 EDT 2016


I've noticed a strange problem when trying to use my InCommon credentials
to login to the Educause site.  This happened when I was trying to test the
various SP sites that my IdP serves as part of our V3 upgrade process.
I'll choose the option for InCommon login and select my University.  I
immediately get a 404 Not Found error.  On the error page, it seems to have
the icon for Ping Identity.  A SAML trace of this shows that on the POST
command to *https://sso.educause.edu/idp/profile/SAML2/POST/SSO
<https://sso.educause.edu/idp/profile/SAML2/POST/SSO>  *I get the following
message:

*POST https://sso.educause.edu/idp/profile/SAML2/POST/SSO
<https://sso.educause.edu/idp/profile/SAML2/POST/SSO> HTTP/1.1
**Host*: sso.educause.edu*User-Agent*: Mozilla/5.0 (Windows NT 10.0;
WOW64; rv:44.0) Gecko/20100101 Firefox/44.0*Accept*:
text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8*Accept-Language*:
en-US,en;q=0.5*Accept-Encoding*: gzip, deflate, br*Referer*:
https://sso.educause.edu*Cookie*:
SESS11c82da70b97151cc5783fcd426abe31=vh1vrbaeb98bqfk0r9hqosgdk1;
PF=pyUbt4P8Np4sO4otTKvtLn*Content-Type*:
application/x-www-form-urlencoded*Content-Length*: 492
*HTTP/?.? 404 Not Found
**Date*: Mon, 14 Mar 2016 21:14:32 GMT*content-security-policy*:
referrer origin*X-Frame-Options*: SAMEORIGIN*Pragma*:
no-cache*Content-Type*: text/html; charset=UTF-8*Cache-Control*:
must-revalidate,no-cache,no-store*Content-Length*: 1323


And the SAML packet:

<samlp:AuthnRequest Version="2.0"
                    ID="_s2dqjGWhd0_BZ3SfGxjNxeBj4B"
                    IssueInstant="2016-03-14T21:14:31.758Z"
                    xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
                    >
    <saml:Issuer
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://sso.educause.edu/sp</saml:Issuer>
    <samlp:NameIDPolicy AllowCreate="true" />
</samlp:AuthnRequest>


In terms of the IdP, there are absolutely no mentions in
idp-process.log (using logging level of debug) of a connection to
educause at all.

Strangely, this same behavior seems to be happening when I switch back
to our V2 IdP.  I was able to connect using both versions of the IdP.

Any suggestions on what this might be and how to troubleshoot the problem?


Thanks,

Mike
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160314/73206d15/attachment.html>


More information about the users mailing list