Logging relyingPartyId (service provider) for authentication failures
MacDonald, Michael J.
Michael.MacDonald at tufts.edu
Wed Mar 1 16:20:10 EST 2017
Is there an easy way to append the relyingPartyId / ServiceProvider name for authentication failures in Shibboleth in either idp-audit.log or idp-proces.log?
As far as I can tell you can't log authentication failures in idp-audit.log. Is that correct?
I'm trying to track authentication failures by relayingParty and idp.remote_addr. We added source IP to our idp_audit.log and idp_process.log and that works fine but I'm wondering if there is a way to keep track of authentication failures by the originating service provider somehow? Is it maybe another place that I am not looking?
Example in idp-process.log
2017-03-01 16:12:54,292 - INFO [org.ldaptive.auth.Authenticator:259] - Authentication failed for dn: edutrunk=**removed**, ou=People, dc=foobar, dc=edu|130.x.x.x
2017-03-01 16:12:54,294 - INFO [net.shibboleth.idp.authn.impl.ValidateUsernamePasswordAgainstJAAS:156] - Profile Action ValidateUsernamePasswordAgainstJAAS: Login by myusername failedjavax.security.auth.login.LoginException: Authentication failed: [org.ldaptive.auth.AuthenticationResponse at 1139902665::authenticationResultCode=AUTHENTICATION_HANDLER_FAILURE, ldapEntry=[dn=edutrunk=**removed*, ou=People, dc=foobar, dc=edu[]], accountState=null, result=false, resultCode=INVALID_CREDENTIALS, message=javax.naming.AuthenticationException: [LDAP: error code 49 - Invalid Credentials], controls=null]
at org.ldaptive.jaas.LdapLoginModule.login(LdapLoginModule.java:160)
|130.x.x.x
Thanks,
-Mike
Michael MacDonald
Tufts University
Tufts Technology Services (TTS)
169 Holland Street, Suite 303
Somerville, MA 02144
617-627-4249
michael.macdonald at tufts.edu<mailto:michael.macdonald at tufts.edu>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170301/050c3f3b/attachment.html>
More information about the users
mailing list