Danish nemlogin, URL is malformed.
Bo Lorentsen
bl at moch.dk
Wed Jun 27 09:40:21 EDT 2018
Hi ...
Yesterday I was so happy, we manage to get shibboleth to successfully
send AuthRequests using sha256 signing, and it all seems so nice when we
got us self a nice valid assert response.
But today, we found that some users ends up with a shibboleth "URL is
malformed" page.
In desperation, I have turned up the debug level in the shibd.logger (I
am on debian linux), to see if something goes wrong, or if some mappings
misbehaved, but it all seems fine, even with all this nice debugging.
It seems like the mapping worked, no errors (a few missing values, in
both cases), it seems to store the session and then it redirects, here
is the log (changed a few minor things like urls) :
2018-06-27 12:07:56 DEBUG XMLTooling.StorageService [2]: inserted record
(_035f6984-e305-4a4d-9f44-3d3e00f05a74) in context
(_99e7b5d183d11bdd686ebb9618e9d088) with expiration (1530104876)
2018-06-27 12:07:56 INFO Shibboleth.SessionCache [2]: new session
created: ID (_99e7b5d183d11bdd686ebb9618e9d088) IdP
(https://saml.nemlog-in.dk)
Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (213.32.247.234)
2018-06-27 12:07:56 DEBUG Shibboleth.SSO.SAML2 [2]: ACS returning via
redirect to: https%3A%2F%2Fxxx.example.io%2Fsso
So, it seems to me that we map the attributes (no conversion errors),
and store the session, and then redirects. But the problem that trigger
the error page, is not visible here, and I don't really know where to look.
Can anyone give me, as to where to look ?
/BL
Ps.: I have attached the assertion XML, where i removed sensitive or not
needed info, is anyone wonder :-)
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ssi_assert_fmt.xml
Type: text/xml
Size: 15242 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20180627/302ebf98/attachment.xml>
More information about the users
mailing list