SimpleAttributePredicate case insensitive
Andrew Morgan
morgan at orst.edu
Thu Feb 16 14:53:46 EST 2017
On Thu, 16 Feb 2017, Cantor, Scott wrote:
>> On a related note - why doesn't the IDP log when access is denied (the
>> context check fails)? All I see is an audit entry with no nameID or
>> attributes listed.
>
> I'd have to look at it, my recollection was that any time there's a
> non-proceed termination of a request, that gets logged on the process
> side and then from an audit standpoint, it definitely logs if you want
> it to, but you can't be using the default log format from V2 and get
> anything useful out. It doesn't log enough fields to distinguish those
> cases.
>
> Safe to say we'll dump that useless format in V4, it probably wasn't all
> that useful to keep it even now.
I haven't changed any of the log levels from the distribution-provided
defaults. Here is exactly what I get in idp-process.log:
2017-02-16 09:55:14,425 - INFO [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstLDAP:152] - Profile Action ValidateUsernamePasswordAgainstLDAP: Login by 'morgan' succeeded
2017-02-16 09:55:21,187 - INFO [net.shibboleth.idp.authn.duo.impl.ValidateDuoWebResponse:202] - Profile Action ValidateDuoWebResponse: Duo authentication succeeded for 'morgan'
2017-02-16 09:55:21,559 - INFO [Shibboleth-Audit.SSO:241] - 20170216T175521Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|hileacmbiabodhoenmflhdlfgcbclbcimpcachop|google.com/a/gtest.onid.oregonstate.edu|http://shibboleth.net/ns/profiles/saml2/sso/browser|https://login.oregonstate.edu/idp-dev/shibboleth|||morgan|||||
In my browser, I get the "Access Denied" page.
Can you look into why there is no error logged?
Thanks,
Andy
More information about the users
mailing list