[EXTERNAL] Re: Logon is looping after apparent successful authentication.
O'Quinn, Dennis
DENNIS_OQUINN at homedepot.com
Fri Jun 1 19:30:28 EDT 2018
If it will help, please refer to the shibd.log excerpt below (minus DEBUG entries for brevity) of a single logon attempt with looping.....
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" Destination="https://thdsaml-qa.homedepot.com/idp/SSO.saml2" ID="_791676d18ee3daf6cd8e232d76749449" IssueInstant="2018-06-01T23:23:30Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://sascloud.homedepot.com/shibboleth</saml:Issuer><samlp:NameIDPolicy AllowCreate="1"/></samlp:AuthnRequest>
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" Destination="https://thdsaml-qa.homedepot.com/idp/SSO.saml2" ID="_9bc12568e2e7bb08337f3b2a86efc38e" IssueInstant="2018-06-01T23:23:32Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://sascloud.homedepot.com/shibboleth</saml:Issuer><samlp:NameIDPolicy AllowCreate="1"/></samlp:AuthnRequest>
<samlp:Response Version="2.0" ID="lA0NJB_l0da3YaEhENM-CyUgNbF" IssueInstant="2018-06-01T23:24:05.138Z" InResponseTo="_9bc12568e2e7bb08337f3b2a86efc38e" Destination="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://devsaml.homedepot.com</saml:Issuer><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference URI="#lA0NJB_l0da3YaEhENM-CyUgNbF">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>i86pQLQL9Lhgu2jUi6vGZS78q0xZPM1QZVyX7ZiMadE=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
LhLj/Fsg0j0PIkErgQyh80W7M+Cai42M34PjFZ1dz4cbUOlSawk3hHs492RiiHbNTS8aQo+AKs9k
43ZyXhxyKDrkEKYWxM04wJVLUGBODjwpS2X8gtJx11kkQHXUD8px2FgigHcEJhph+XffX0ScIDMV
m7kzx1qIG++mQxs+IVTM+gfkrTsE9FdcrWw+y7CUl5PJl1n9qrI/FfNuqHIC6IuXEb7vCf1YVMXH
rliAUmop01vzcAabvMnANZ4RkwHA5y4n7jKLL8X/GkgIsNnDkK6/5xccv85YflfE/yb4WUlYffEq
Aki3QWW0KJsMlOJg9XypTiYfzjOj6k+qPZxiog==
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
.
.
.
</ds:X509Certificate>
</ds:X509Data>
<ds:KeyValue>
<ds:RSAKeyValue>
<ds:Modulus>
h0AUJ3RAXh8tIl009Dq/i6vT1dQVBZ+/+NDysj2FPd5JYs7QFkjVgRJVRR0tXSJ2o/rA1KzSX982
mvLJLxvkW0BwDf47EjeZGj5ZZVi5nG22WAeMpLyRa2hnKCmD3hoeUnaRF7wzsWJpC1nYCdLiafN3
syd6ayPrjVr6Rwz/Yd8QAgkXu+hBy70xFKSdAb4NqSu+nEZzAsDsGXCF3fH9iMBsmsLXaghZmm2Y
N83tYTFpxR1vfWGo2YMGN10xGWYsBvxv3Q2jtLYXjHdqBOD3Ng2tGWKYNJqlYgGbE/OdbjrKjd03
Ln1fRgZCtW1/Vr+tbixAEC7QBJPioSAPwYTM2Q==
</ds:Modulus>
<ds:Exponent>AQAB</ds:Exponent>
</ds:RSAKeyValue>
</ds:KeyValue>
</ds:KeyInfo>
</ds:Signature><samlp:Status><samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></samlp:Status><saml:Assertion ID="byLxpEApvoSAOCI9VB5g8xaqpAG" IssueInstant="2018-06-01T23:24:05.871Z" Version="2.0" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><saml:Issuer>https://devsaml.homedepot.com</saml:Issuer><saml:Subject><saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">dxo5ic1</saml:NameID><saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml:SubjectConfirmationData Recipient="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" NotOnOrAfter="2018-06-01T23:39:05.871Z" InResponseTo="_9bc12568e2e7bb08337f3b2a86efc38e"/></saml:SubjectConfirmation></saml:Subject><saml:Conditions NotBefore="2018-06-01T23:14:05.871Z" NotOnOrAfter="2018-06-01T23:39:05.871Z"><saml:AudienceRestriction><saml:Audience>https://sascloud.homedepot.com/shibboleth</saml:Audience></saml:AudienceRestriction></saml:Conditions><saml:AuthnStatement SessionIndex="byLxpEApvoSAOCI9VB5g8xaqpAG" AuthnInstant="2018-06-01T23:24:05.871Z"><saml:AuthnContext><saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef></saml:AuthnContext></saml:AuthnStatement></saml:Assertion></samlp:Response>
2018-06-01 19:24:05 WARN Shibboleth.AttributeResolver.Query [3]: no SAML 2 AttributeAuthority role found in metadata
2018-06-01 19:24:05 INFO Shibboleth.SessionCache [3]: new session created: ID (_92085e8ccf790e5f7646ef58878446d8) IdP (https://devsaml.homedepot.com) Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (130.211.3.197)
2018-06-01 19:24:05 INFO Shibboleth.SessionCache [4]: removed session (_92085e8ccf790e5f7646ef58878446d8)
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" Destination="https://thdsaml-qa.homedepot.com/idp/SSO.saml2" ID="_14c249f7768cb7151d66bf5c69cc1847" IssueInstant="2018-06-01T23:24:05Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://sascloud.homedepot.com/shibboleth</saml:Issuer><samlp:NameIDPolicy AllowCreate="1"/></samlp:AuthnRequest>
<samlp:Response Version="2.0" ID="KBUeNypUjlM8ZrkBE5PQ6YaQ.2d" IssueInstant="2018-06-01T23:24:06.074Z" InResponseTo="_14c249f7768cb7151d66bf5c69cc1847" Destination="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://devsaml.homedepot.com</saml:Issuer><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference URI="#KBUeNypUjlM8ZrkBE5PQ6YaQ.2d">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>gnNPYoU64H7CA3Vz+gQMQbayAl5k9svxnEVhaAT/a70=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
HPXPJaBxkElzzH7nlsA+SPE8svcT4VNKtsa3UPj9J64tK9R7fLFhUfHtyzjcOLThruYSKOGKnCz+
AnxSauylSLhOx9yPMXnsAKyCag6601GDprjqHfXnM74ky5qLtRVVvxBPTRbUYPOw39GADDWe8FmF
XNhvr3vBUJ0OCUBiM2dBwDn3fWnf5/AyMlXIt6yf2sUYC6NEvLsIbRp6nonj0wtRpLDM+A/b5h+m
MEYE1nx42WztIVkO3l+tei7Z5ohL74kvxymfnpN38wJvig+EwwOacOK+u9EVZLF8x3qs9L3oTKnr
7fhlwpzuBB+LR+Tl1qeFtYI/G7jgWTTb02SLfw==
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
.
.
.
</ds:X509Certificate>
</ds:X509Data>
<ds:KeyValue>
<ds:RSAKeyValue>
<ds:Modulus>
h0AUJ3RAXh8tIl009Dq/i6vT1dQVBZ+/+NDysj2FPd5JYs7QFkjVgRJVRR0tXSJ2o/rA1KzSX982
mvLJLxvkW0BwDf47EjeZGj5ZZVi5nG22WAeMpLyRa2hnKCmD3hoeUnaRF7wzsWJpC1nYCdLiafN3
syd6ayPrjVr6Rwz/Yd8QAgkXu+hBy70xFKSdAb4NqSu+nEZzAsDsGXCF3fH9iMBsmsLXaghZmm2Y
N83tYTFpxR1vfWGo2YMGN10xGWYsBvxv3Q2jtLYXjHdqBOD3Ng2tGWKYNJqlYgGbE/OdbjrKjd03
Ln1fRgZCtW1/Vr+tbixAEC7QBJPioSAPwYTM2Q==
</ds:Modulus>
<ds:Exponent>AQAB</ds:Exponent>
</ds:RSAKeyValue>
</ds:KeyValue>
</ds:KeyInfo>
</ds:Signature><samlp:Status><samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></samlp:Status><saml:Assertion ID="dTXaWwtGfc3wAC.BNK.vcdFdS1b" IssueInstant="2018-06-01T23:24:07.182Z" Version="2.0" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><saml:Issuer>https://devsaml.homedepot.com</saml:Issuer><saml:Subject><saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">dxo5ic1</saml:NameID><saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml:SubjectConfirmationData Recipient="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" NotOnOrAfter="2018-06-01T23:39:07.182Z" InResponseTo="_14c249f7768cb7151d66bf5c69cc1847"/></saml:SubjectConfirmation></saml:Subject><saml:Conditions NotBefore="2018-06-01T23:14:07.182Z" NotOnOrAfter="2018-06-01T23:39:07.182Z"><saml:AudienceRestriction><saml:Audience>https://sascloud.homedepot.com/shibboleth</saml:Audience></saml:AudienceRestriction></saml:Conditions><saml:AuthnStatement SessionIndex="dTXaWwtGfc3wAC.BNK.vcdFdS1b" AuthnInstant="2018-06-01T23:24:07.182Z"><saml:AuthnContext><saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef></saml:AuthnContext></saml:AuthnStatement></saml:Assertion></samlp:Response>
2018-06-01 19:24:07 WARN Shibboleth.AttributeResolver.Query [1]: no SAML 2 AttributeAuthority role found in metadata
2018-06-01 19:24:07 INFO Shibboleth.SessionCache [1]: new session created: ID (_6b8bdc09d01b11e21b75427b68a5e713) IdP (https://devsaml.homedepot.com) Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (130.211.3.168)
2018-06-01 19:24:07 INFO Shibboleth.SessionCache [2]: removed session (_6b8bdc09d01b11e21b75427b68a5e713)
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" Destination="https://thdsaml-qa.homedepot.com/idp/SSO.saml2" ID="_4b76c68699f08701f2a1f890ad5abf74" IssueInstant="2018-06-01T23:24:07Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://sascloud.homedepot.com/shibboleth</saml:Issuer><samlp:NameIDPolicy AllowCreate="1"/></samlp:AuthnRequest>
<samlp:Response Version="2.0" ID="wOaA0UTEfPJUYEfXtb6eGY2CkiG" IssueInstant="2018-06-01T23:24:07.353Z" InResponseTo="_4b76c68699f08701f2a1f890ad5abf74" Destination="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://devsaml.homedepot.com</saml:Issuer><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference URI="#wOaA0UTEfPJUYEfXtb6eGY2CkiG">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>sjJt/Zkan/pfc3ZS13qD1wKDsHpF5IAtEjDbMrLM0s8=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
UdL31SxknBa52E+i6vwM7EP7HFiqE6MsfZglpZagGWiSscBSaF6EW30XVnMrV0OaHg4+H1p5TUPo
H4FKmwEk73kIyMgtOhZVXyXRTR4/r+Bf6eW6HOl8cVe8teVAIHDVbqxUW4XOO7HseVXen1qFPfa6
ZWNdnH9g/nYS1nfmCIbGtUMBm+X02XTEARiFNZc4fExtq9HzKHP4XZSgqOIU1NuIn3700rum3Yo2
fzUwqNiFd05W8Q/aicrsGCUk+edLUQ0IRWhabuUOuKkBb9YdVF//AMEn+XLtAU0wyR8u8nWWDyx8
lhZkqKyJkLFosA3PBGAbOHllCGlFtFNV9o6RVA==
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
.
.
.
</ds:X509Certificate>
</ds:X509Data>
<ds:KeyValue>
<ds:RSAKeyValue>
<ds:Modulus>
h0AUJ3RAXh8tIl009Dq/i6vT1dQVBZ+/+NDysj2FPd5JYs7QFkjVgRJVRR0tXSJ2o/rA1KzSX982
mvLJLxvkW0BwDf47EjeZGj5ZZVi5nG22WAeMpLyRa2hnKCmD3hoeUnaRF7wzsWJpC1nYCdLiafN3
syd6ayPrjVr6Rwz/Yd8QAgkXu+hBy70xFKSdAb4NqSu+nEZzAsDsGXCF3fH9iMBsmsLXaghZmm2Y
N83tYTFpxR1vfWGo2YMGN10xGWYsBvxv3Q2jtLYXjHdqBOD3Ng2tGWKYNJqlYgGbE/OdbjrKjd03
Ln1fRgZCtW1/Vr+tbixAEC7QBJPioSAPwYTM2Q==
</ds:Modulus>
<ds:Exponent>AQAB</ds:Exponent>
</ds:RSAKeyValue>
</ds:KeyValue>
</ds:KeyInfo>
</ds:Signature><samlp:Status><samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></samlp:Status><saml:Assertion ID="cOcMER-67wiRBl85DFoJ4X99iEk" IssueInstant="2018-06-01T23:24:08.336Z" Version="2.0" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><saml:Issuer>https://devsaml.homedepot.com</saml:Issuer><saml:Subject><saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">dxo5ic1</saml:NameID><saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml:SubjectConfirmationData Recipient="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" NotOnOrAfter="2018-06-01T23:39:08.336Z" InResponseTo="_4b76c68699f08701f2a1f890ad5abf74"/></saml:SubjectConfirmation></saml:Subject><saml:Conditions NotBefore="2018-06-01T23:14:08.336Z" NotOnOrAfter="2018-06-01T23:39:08.336Z"><saml:AudienceRestriction><saml:Audience>https://sascloud.homedepot.com/shibboleth</saml:Audience></saml:AudienceRestriction></saml:Conditions><saml:AuthnStatement SessionIndex="cOcMER-67wiRBl85DFoJ4X99iEk" AuthnInstant="2018-06-01T23:24:08.336Z"><saml:AuthnContext><saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef></saml:AuthnContext></saml:AuthnStatement></saml:Assertion></samlp:Response>
2018-06-01 19:24:08 WARN Shibboleth.AttributeResolver.Query [3]: no SAML 2 AttributeAuthority role found in metadata
2018-06-01 19:24:08 INFO Shibboleth.SessionCache [3]: new session created: ID (_976031c307ebce747c851d1dc07173ad) IdP (https://devsaml.homedepot.com) Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (130.211.2.221)
2018-06-01 19:24:08 INFO Shibboleth.SessionCache [4]: removed session (_976031c307ebce747c851d1dc07173ad)
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" Destination="https://thdsaml-qa.homedepot.com/idp/SSO.saml2" ID="_919958a133397506a3ed0f7d5a9a6919" IssueInstant="2018-06-01T23:24:08Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://sascloud.homedepot.com/shibboleth</saml:Issuer><samlp:NameIDPolicy AllowCreate="1"/></samlp:AuthnRequest>
<samlp:Response Version="2.0" ID="DEjtQGvrOS7H-VingZ.rvuBX0wg" IssueInstant="2018-06-01T23:24:08.539Z" InResponseTo="_919958a133397506a3ed0f7d5a9a6919" Destination="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://devsaml.homedepot.com</saml:Issuer><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference URI="#DEjtQGvrOS7H-VingZ.rvuBX0wg">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>rEodhDhnxS+nqk5xmIPz3pJnh5SjED7Ms2f0gAMBGlg=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
E+7Kb999IDkQIqlu9T+3c3LpqEPNaPm7lkToZnqCW9/ltjsZptqqaZDgnI8CMpdnkq5DEhsSGTsw
JwanBrFV2Z021BReg9zzMHaV37dlHUu801WjwwjJ3TuEFGbzbqEQdQHt4No5ml06QzOEgl++cfo1
ANq6az76ySB6b1LvdmzjaAcQ7mHXLM+bV1lyhQYge2LNBO2V9FcGZxkaf311NQVjXuPGFNXSIdre
0k/3RKzoNfcJ76EigkjvHFkMKS/ZHyFWlNWPwd50vcaZHayl2tXyeTLbLh7847B0Y4lISVjXCH2Q
g2VJP9gqfitD8I2rMpE0ZraFBCVP2SvK+ud+cw==
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
.
.
.
</ds:X509Certificate>
</ds:X509Data>
<ds:KeyValue>
<ds:RSAKeyValue>
<ds:Modulus>
h0AUJ3RAXh8tIl009Dq/i6vT1dQVBZ+/+NDysj2FPd5JYs7QFkjVgRJVRR0tXSJ2o/rA1KzSX982
mvLJLxvkW0BwDf47EjeZGj5ZZVi5nG22WAeMpLyRa2hnKCmD3hoeUnaRF7wzsWJpC1nYCdLiafN3
syd6ayPrjVr6Rwz/Yd8QAgkXu+hBy70xFKSdAb4NqSu+nEZzAsDsGXCF3fH9iMBsmsLXaghZmm2Y
N83tYTFpxR1vfWGo2YMGN10xGWYsBvxv3Q2jtLYXjHdqBOD3Ng2tGWKYNJqlYgGbE/OdbjrKjd03
Ln1fRgZCtW1/Vr+tbixAEC7QBJPioSAPwYTM2Q==
</ds:Modulus>
<ds:Exponent>AQAB</ds:Exponent>
</ds:RSAKeyValue>
</ds:KeyValue>
</ds:KeyInfo>
</ds:Signature><samlp:Status><samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></samlp:Status><saml:Assertion ID="CC6xukdcP3heMrxBUaZsN_QAW38" IssueInstant="2018-06-01T23:24:09.584Z" Version="2.0" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><saml:Issuer>https://devsaml.homedepot.com</saml:Issuer><saml:Subject><saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">dxo5ic1</saml:NameID><saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml:SubjectConfirmationData Recipient="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" NotOnOrAfter="2018-06-01T23:39:09.584Z" InResponseTo="_919958a133397506a3ed0f7d5a9a6919"/></saml:SubjectConfirmation></saml:Subject><saml:Conditions NotBefore="2018-06-01T23:14:09.584Z" NotOnOrAfter="2018-06-01T23:39:09.584Z"><saml:AudienceRestriction><saml:Audience>https://sascloud.homedepot.com/shibboleth</saml:Audience></saml:AudienceRestriction></saml:Conditions><saml:AuthnStatement SessionIndex="CC6xukdcP3heMrxBUaZsN_QAW38" AuthnInstant="2018-06-01T23:24:09.584Z"><saml:AuthnContext><saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef></saml:AuthnContext></saml:AuthnStatement></saml:Assertion></samlp:Response>
2018-06-01 19:24:09 WARN Shibboleth.AttributeResolver.Query [3]: no SAML 2 AttributeAuthority role found in metadata
2018-06-01 19:24:09 INFO Shibboleth.SessionCache [3]: new session created: ID (_53ac1bab9c3efca559d3f5ff7b81dcce) IdP (https://devsaml.homedepot.com) Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (130.211.3.197)
2018-06-01 19:24:09 INFO Shibboleth.SessionCache [1]: removed session (_53ac1bab9c3efca559d3f5ff7b81dcce)
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="https://sascloud.homedepot.com/Shibboleth.sso/SAML2/POST" Destination="https://thdsaml-qa.homedepot.com/idp/SSO.saml2" ID="_4395dc36d7dd554a2347b4dd8e1014ff" IssueInstant="2018-06-01T23:24:09Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://sascloud.homedepot.com/shibboleth</saml:Issuer><samlp:NameIDPolicy AllowCreate="1"/></samlp:AuthnRequest>
[root at sas-mao-midtier shibboleth]#
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of O'Quinn, Dennis
Sent: Friday, June 1, 2018 7:11 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: [EXTERNAL] Re: Logon is looping after apparent successful authentication.
Hi Scott, thank you for your continued (and fast) responses.
Sorry, I did not get what you were... no clustering... I am only saying that as I look in the chrome dev tools network trace data, I am seeing 'cookies' represented on the 3 network trace 'entry names' I mentioned... That is all that is in the network trace due to the looping.
The setup is:
-> A corporate network where the PingIdentity IdP is hosted.
-> There is a Google Cloud Load Balancer with a front end facing this corporate network listening on port 443.
-> The DNS name for this LB front end is sascloud.homedepot.com (note: the LB reference is not significant, it is only serving as the gateway into the cloud and has only 1 node in its 'pool' (i.e., the SAS Web Server)).
-> The LB back end (i.e., inside GCP) points to the SAS Web Server (Linux/Apache 2.4/Shibboleth 2.6.1) where the SP function is hosted. The host name of the SAS Web Server in GCP is sas-mao-midtier.<GCP Domain> and it is listening on port 8343.
-> Both the front-end and the backend connections for the LB are HTTPS .
-> The URLs in the SP Metadata provided to the IdP are all prefixed as "https://sascloud.homedepot.com/".
-> The ServerName directive in the httpd-ssl.conf file on the SAS Web
-> Server is set to sascloud.homedepot.com and a ServerAlias is defined
-> for sas-mao-midtier.<GCP Domain>:8343
The login seems to be working fine.
One possible complication here is that we are doing 2 factor authentication at the IdP, so, the user is first prompted to authenticate using an ID/RSA Token, and then the user is prompted to authenticate again using an ID/PSW that is authenticated via LDAPS.
I do not believe the 2FA is a problem though since we were also looping when doing the RSA token only. I only mention it to be complete.
Questions:
Would I find the information I need to debug this in the shibd_warm.log or the shibd.log or the native(or native_warn).log?
NOTE: I believe I have all of the debug settings enabled in the shibboleth log config files in /etc/shibboleth, so, I am getting a copious amount of information in my logs.
I apologize if I am missing something obvious, but, I am still getting my head around Shibboleth and SAML, so, there are (apparently) quite a few things that I don't know or completely understand yet.
Thanks much, Dennis
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Friday, June 1, 2018 6:10 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: [EXTERNAL] Re: Logon is looping after apparent successful authentication.
> I can ‘view’ the cookies in Chrome, and am using the dev tools in
> chrome plus a SAML tracer, but, that doesn’t tell me what is ‘bad’
> about the cookies. I see that on the POST, my app URL, and the
> SSO.saml2?SAMLRequest named entries in the Network Trace data all have the same cookie.
That’s impossible so you're not looking at the right cookies. Two different servers don't share cookies in these exchanges.
POST -> Set-Cookie header from the SP with shibsession in the name.
Redirect -> Get -> send Cookie header back to the SP
There is no way that's happening. Or you have logs somewhere indicating it invalidated the session because even if it did happen the IP address flipped or something else is wrong.
Perhaps you have clustered this across servers with no regard for the fact that that simply doesn't work, the cache is in memory.
-- Scott
--
For Consortium Member technical support, see https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwIGaQ&c=MtgQEAMQGqekjTjiAhkudQ&r=mn6DeBt1nj8Oqx06pdIK0_n5EfK6FeVHgdjBNpchyro&m=QUTg05SvLnheWFas8BBmp-im0nlIxm8CO4FpoRgGd9Y&s=seSyKO6fX0rdUgjZnWPmmOCycuM6a8whlHJFejOd9K0&e=
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
________________________________
The information in this Internet Email is confidential and may be legally privileged. It is intended solely for the addressee. Access to this Email by anyone else is unauthorized. If you are not the intended recipient, any disclosure, copying, distribution or any action taken or omitted to be taken in reliance on it, is prohibited and may be unlawful. When addressed to our clients any opinions or advice contained in this Email are subject to the terms and conditions expressed in any applicable governing The Home Depot terms of business or client engagement letter. The Home Depot disclaims all responsibility and liability for the accuracy and content of this attachment and for any damages or losses arising from any inaccuracies, errors, viruses, e.g., worms, trojan horses, etc., or other items of a destructive nature, which may be contained in this attachment and shall not be liable for direct, indirect, consequential or special damages in connection with this e-mail message or its attachment.
--
For Consortium Member technical support, see https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwIGaQ&c=MtgQEAMQGqekjTjiAhkudQ&r=mn6DeBt1nj8Oqx06pdIK0_n5EfK6FeVHgdjBNpchyro&m=giPMBy2Meo2VxIoalQgYTFfoATuZcLhoEHEKGqN4CFI&s=HYKW0ad0YWv5u683CYyVwHbb8EVrHWoZTyKQ8pZG6KQ&e=
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
________________________________
The information in this Internet Email is confidential and may be legally privileged. It is intended solely for the addressee. Access to this Email by anyone else is unauthorized. If you are not the intended recipient, any disclosure, copying, distribution or any action taken or omitted to be taken in reliance on it, is prohibited and may be unlawful. When addressed to our clients any opinions or advice contained in this Email are subject to the terms and conditions expressed in any applicable governing The Home Depot terms of business or client engagement letter. The Home Depot disclaims all responsibility and liability for the accuracy and content of this attachment and for any damages or losses arising from any inaccuracies, errors, viruses, e.g., worms, trojan horses, etc., or other items of a destructive nature, which may be contained in this attachment and shall not be liable for direct, indirect, consequential or special damages in connection with this e-mail message or its attachment.
More information about the users
mailing list