Educause SP login
Michael Dahlberg
olgamirth at gmail.com
Mon Mar 14 17:27:18 EDT 2016
I've noticed a strange problem when trying to use my InCommon credentials
to login to the Educause site. This happened when I was trying to test the
various SP sites that my IdP serves as part of our V3 upgrade process.
I'll choose the option for InCommon login and select my University. I
immediately get a 404 Not Found error. On the error page, it seems to have
the icon for Ping Identity. A SAML trace of this shows that on the POST
command to *https://sso.educause.edu/idp/profile/SAML2/POST/SSO
<https://sso.educause.edu/idp/profile/SAML2/POST/SSO> *I get the following
message:
*POST https://sso.educause.edu/idp/profile/SAML2/POST/SSO
<https://sso.educause.edu/idp/profile/SAML2/POST/SSO> HTTP/1.1
**Host*: sso.educause.edu*User-Agent*: Mozilla/5.0 (Windows NT 10.0;
WOW64; rv:44.0) Gecko/20100101 Firefox/44.0*Accept*:
text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8*Accept-Language*:
en-US,en;q=0.5*Accept-Encoding*: gzip, deflate, br*Referer*:
https://sso.educause.edu*Cookie*:
SESS11c82da70b97151cc5783fcd426abe31=vh1vrbaeb98bqfk0r9hqosgdk1;
PF=pyUbt4P8Np4sO4otTKvtLn*Content-Type*:
application/x-www-form-urlencoded*Content-Length*: 492
*HTTP/?.? 404 Not Found
**Date*: Mon, 14 Mar 2016 21:14:32 GMT*content-security-policy*:
referrer origin*X-Frame-Options*: SAMEORIGIN*Pragma*:
no-cache*Content-Type*: text/html; charset=UTF-8*Cache-Control*:
must-revalidate,no-cache,no-store*Content-Length*: 1323
And the SAML packet:
<samlp:AuthnRequest Version="2.0"
ID="_s2dqjGWhd0_BZ3SfGxjNxeBj4B"
IssueInstant="2016-03-14T21:14:31.758Z"
xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
>
<saml:Issuer
xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://sso.educause.edu/sp</saml:Issuer>
<samlp:NameIDPolicy AllowCreate="true" />
</samlp:AuthnRequest>
In terms of the IdP, there are absolutely no mentions in
idp-process.log (using logging level of debug) of a connection to
educause at all.
Strangely, this same behavior seems to be happening when I switch back
to our V2 IdP. I was able to connect using both versions of the IdP.
Any suggestions on what this might be and how to troubleshoot the problem?
Thanks,
Mike
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160314/73206d15/attachment.html>
More information about the users
mailing list