Logout problem with Office 365

cronzero sebastian.majewski at poczta.umcs.lublin.pl
Tue Nov 29 07:54:27 EST 2016


Hi.

I have working IDP 3.2. 
Users can login and logout to SPs. 
Users can login to Office365 but any attempts of logout fail:
2016-11-29 13:24:16,052 - DEBUG
[org.opensaml.security.credential.criteria.impl.EvaluableCredentialCriteriaRegistry:81]
- Registry located evaluable criteria class
org.opensaml.security.credential.criteria.impl.EvaluableKeyAlgorithmCredentialCriterion
for criteria class org.opensaml.security.criteria.KeyAlgorithmCriterion
2016-11-29 13:24:16,052 - DEBUG
[org.opensaml.security.credential.criteria.impl.EvaluableCredentialCriteriaRegistry:96]
- Registry could not locate evaluable criteria for criteria class
org.opensaml.saml.criterion.EntityRoleCriterion
2016-11-29 13:24:16,053 - DEBUG
[org.opensaml.security.credential.criteria.impl.EvaluableCredentialCriteriaRegistry:96]
- Registry could not locate evaluable criteria for criteria class
org.opensaml.saml.criterion.ProtocolCriterion
2016-11-29 13:24:16,053 - DEBUG
[org.opensaml.security.credential.criteria.impl.EvaluableCredentialCriteriaRegistry:96]
- Registry could not locate evaluable criteria for criteria class
org.opensaml.xmlsec.signature.support.SignatureValidationParametersCriterion
2016-11-29 13:24:16,054 - DEBUG
[org.opensaml.security.credential.criteria.impl.EvaluableCredentialCriteriaRegistry:81]
- Registry located evaluable criteria class
org.opensaml.security.credential.criteria.impl.EvaluableEntityIDCredentialCriterion
for criteria class org.opensaml.core.criterion.EntityIdCriterion
2016-11-29 13:24:16,055 - DEBUG
[org.opensaml.security.credential.criteria.impl.EvaluableCredentialCriteriaRegistry:81]
- Registry located evaluable criteria class
org.opensaml.security.credential.criteria.impl.EvaluableUsageCredentialCriterion
for criteria class org.opensaml.security.criteria.UsageCriterion
2016-11-29 13:24:16,055 - DEBUG
[org.opensaml.xmlsec.signature.support.impl.ExplicitKeySignatureTrustEngine:173]
- Attempting to verify signature using trusted credentials
2016-11-29 13:24:16,056 - DEBUG
[org.opensaml.security.crypto.SigningUtil:210] - Verifying signature over
input using public key of type RSA and JCA algorithm ID SHA1withRSA
2016-11-29 13:24:16,057 - DEBUG
[org.opensaml.security.crypto.SigningUtil:210] - Verifying signature over
input using public key of type RSA and JCA algorithm ID SHA1withRSA
2016-11-29 13:24:16,058 - DEBUG
[org.opensaml.xmlsec.signature.support.impl.ExplicitKeySignatureTrustEngine:186]
- Failed to verify signature using either supplied candidate credential or
directly trusted credentials
2016-11-29 13:24:16,059 - DEBUG
[org.opensaml.xmlsec.signature.support.impl.BaseSignatureTrustEngine:131] -
Performing signature algorithm whitelist/blacklist validation using params
from CriteriaSet
2016-11-29 13:24:16,059 - DEBUG
[org.opensaml.xmlsec.algorithm.AlgorithmSupport:408] - Saw non-null
algorithm blacklist: [http://www.w3.org/2001/04/xmldsig-more#hmac-md5,
http://www.w3.org/2001/04/xmldsig-more#md5,
http://www.w3.org/2001/04/xmldsig-more#rsa-md5]
2016-11-29 13:24:16,060 - DEBUG
[org.opensaml.xmlsec.algorithm.AlgorithmSupport:413] - Algorithm passed
blacklist validation: http://www.w3.org/2000/09/xmldsig#rsa-sha1
2016-11-29 13:24:16,060 - DEBUG
[org.opensaml.xmlsec.algorithm.AlgorithmSupport:420] - Saw non-null
algorithm whitelist: []
2016-11-29 13:24:16,060 - DEBUG
[org.opensaml.xmlsec.algorithm.AlgorithmSupport:429] - Non-null algorithm
whitelist was empty, skipping evaluation
2016-11-29 13:24:16,061 - DEBUG
[org.opensaml.xmlsec.signature.support.impl.PKIXSignatureTrustEngine:172] -
Candidate credential was either not supplied or did not contain verification
key
2016-11-29 13:24:16,061 - DEBUG
[org.opensaml.xmlsec.signature.support.impl.PKIXSignatureTrustEngine:173] -
PKIX trust engine requires supplied key, skipping PKIX trust evaluation
2016-11-29 13:24:16,062 - WARN
[org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:275]
- Message Handler:  Simple signature validation (with no request-derived
credentials) failed
2016-11-29 13:24:16,062 - WARN
[org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:212]
- Message Handler:  Validation of request simple signature failed for
context issuer: urn:federation:MicrosoftOnline
2016-11-29 13:24:16,065 - WARN
[net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:182] - Profile
Action WebFlowMessageHandlerAdaptor: Exception handling message
org.opensaml.messaging.handler.MessageHandlerException: Validation of
request simple signature failed for context issuer
	at
org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler.doEvaluate(BaseSAMLSimpleSignatureSecurityHandler.java:214)
2016-11-29 13:24:16,068 - WARN
[org.opensaml.profile.action.impl.LogEvent:76] - An error event occurred
while processing the request: MessageAuthenticationError
2016-11-29 13:24:16,068 - DEBUG
[org.opensaml.saml.common.profile.logic.DefaultLocalErrorPredicate:154] - No
SAMLBindingContext or binding URI available, error must be handled locally


I am struggling with it for a few days, any clue what to do ?



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Logout-problem-with-Office-365-tp7629829.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list