audit log entry for null CAS service

Andrew Morgan morgan at orst.edu
Tue Nov 14 12:10:27 EST 2017


On Tue, 14 Nov 2017, Cantor, Scott wrote:

>> When a client requests the CAS login page without providing a service, 
>> the IDP returns an error page "An error occurred: ServiceNotSpecified" 
>> and HTTP code 500.  However, it also logs that in the audit log.
>
> The audit log is supposed to be written to as much as possible in 
> response to any query. In the SAML case, we certainly try and log errors 
> unless told otherwise. Of course the default format remains completely 
> useless. I think we settled on dumping the V2 compatibility and just 
> shipping a reasonable default in 3.4, though we ordinarily wouldn't do 
> that before 4.0.

What would a SAML error look like in the audit log?  I see many kinds of 
errors in the process log, but I can only find successful SAML 
authentications in the audit log.

Thanks,
 	Andy


More information about the users mailing list