Getting PowerFAIDS NetPartner to work with Shibboleth 3 - another attempt

Norman Bodnar bodnarn at gmail.com
Thu May 17 16:14:00 EDT 2018


Apologies ahead of time for my newness to this board. I'm starting a new
thread based on the recent one for Netpartner/Shibboleth IdP3...

Note: new IdP3 server is successfully working with other service providers.


My scenario, new netpartner server, new shibboleth server (IdP3, previously
our old netpartner worked with IdP2 server).

I've tried to apply the recent recommendations on this maillist, but I can
never get to my shibboleth logon page. After hitting
https://mynetpartnerserver/NetPartnerStudent, the SAML goes across but
after shibboleth gets it I get directed to a shib page:


The login service was unable to identify a compatible way to respond to the
requested application. This is generally due to a misconfiguration on the
part of the application and should be reported to the application's support
team or owner.





The logs show issue starting here (server names scrubbed)...

2018-05-17 15:19:26,883 - DEBUG
[net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:65]
- Profile Action SelectProfileInterceptorFlow: Moving completed flow
intercept/security-policy/saml2-sso to completed set, selecting next one
2018-05-17 15:19:26,884 - DEBUG
[net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:80]
- Profile Action SelectProfileInterceptorFlow: No flows available to choose
from
2018-05-17 15:19:26,895 - DEBUG
[net.shibboleth.idp.saml.profile.impl.InitializeOutboundMessageContext:149]
- Profile Action InitializeOutboundMessageContext: Initialized outbound
message context
2018-05-17 15:19:26,918 - DEBUG
[net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:375]
- Profile Action PopulateBindingAndEndpointContexts: Attempting to resolve
endpoint of type
{urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService for outbound
message
2018-05-17 15:19:26,920 - DEBUG
[net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:516]
- Profile Action PopulateBindingAndEndpointContexts: Populating template
endpoint for resolution from SAML AuthnRequest
2018-05-17 15:19:26,921 - WARN
[net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:410]
- Profile Action PopulateBindingAndEndpointContexts: Unable to resolve
outbound message endpoint for relying party 'NetPartner': EndpointCriterion
[type={urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService,
Binding=urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST, Location=
https://servernamehere/NetPartnerStudent/Logon.aspx, trusted=false]
2018-05-17 15:19:26,938 - WARN
[org.opensaml.profile.action.impl.LogEvent:105] - A non-proceed event
occurred while processing the request: EndpointResolutionFailed


>From my Firefox developer tools, I see this:

 HTTP400: BAD REQUEST - The request could not be processed by the server
due to invalid syntax.
GET -
https://shibbolethservernamehere/idp/profile/SAML2/Redirect/SSO?SAMLRequest=fZFBb8IwDIXv%2fIood1pAQmMRBTHQNCTGKlp22C00po1onS5OGfv3C93YkCYhJRfHee979nh6qkp2BEvaYMT7QY8zwMwojXnEt%2bljd8Snk86YZFXWYta4Ajfw3gA55j8iifYh4o1FYSRpEigrIOEykcyeV2IQ9ERtjTOZKTlbLiKO%2b6LYaY2q2h92kB2KfIdG1nWtKoA8xz3mgCpTnL1eqAZnqiVRA0skJ9H5Uq8%2f6vaG3f5d2r8X5zN84yz%2bcXrw8m2AW1i77yYST2kad%2bOXJG0FjlqBXfvuiK%2fBxdI6BHu2jyWRPvryXpYEnM2IwDoPODdITQU2AXvUGWw3q4gXztUkwtDTZhaUDqy3Kv0NQDXhn3DiGgXowpXJDQaS6hOfdBhr5y3ayPZq0LcDyQsQn%2fwZjMMrqV%2fpWpwTLhexKXX2yWZlaT7mFqTz8ZxtfDoW%2bq2H%2f9c%2b6XwB&RelayState=%2fNetPartnerStudent%2fDefault.aspx



My shibboleth configurations are as follows (relevant netpartner items
only):

netpartner metadata

<EntityDescriptor entityID="NetPartner"
xmlns="urn:oasis:names:tc:SAML:2.0:metadata">
    <SPSSODescriptor
        protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol
        urn:oasis:names:tc:SAML:1.1:protocol
urn:oasis:names:tc:SAML:1.0:protocol">

<NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat>
    <AssertionConsumerService index="1"
        Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
        Location="
https://servernamehere/NetPartner/NetPartnerStudent/Logon.aspx"/>
    </SPSSODescriptor>
</EntityDescriptor>


metadata-providers.xml

<MetadataProvider id="NetPartnerMetadata"
    xsi:type="FilesystemMetadataProvider"
    xmlns="urn:mace:shibboleth:2.0:metadata"
    metadataFile="%{idp.home}/metadata/netpartner.xml"/>


relying-party.xml

<bean id="SHA1SecurityConfig"
parent="shibboleth.DefaultSecurityConfiguration"

p:signatureSigningConfiguration-ref="shibboleth.SigningConfiguration.SHA1"
/>

Under RelyingPartyOverrides

<bean parent="RelyingPartyByName" c:relyingPartyIds="NetPartner">
    <property name="profileConfigurations">
        <list>
            <bean parent="Shibboleth.SSO"
p:securityConfiguration-ref="SHA1SecurityConfig" />
            <bean parent="SAML1.AttributeQuery"
p:securityConfiguration-ref="SHA1SecurityConfig" />
            <bean parent="SAML1.ArtifactResolution"
p:securityConfiguration-ref="SHA1SecurityConfig" />
            <bean parent="SAML2.ECP"
p:securityConfiguration-ref="SHA1SecurityConfig" />
            <bean parent="SAML2.Logout"
p:securityConfiguration-ref="SHA1SecurityConfig" />
            <bean parent="SAML2.AttributeQuery"
p:securityConfiguration-ref="SHA1SecurityConfig" />
            <bean parent="SAML2.ArtifactResolution"
p:securityConfiguration-ref="SHA1SecurityConfig" />
            <bean parent="SAML2.SSO"
                p:encryptAssertions="false"
                p:securityConfiguration-ref="SHA1SecurityConfig"

p:nameIDFormatPrecedence="#{{'urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified'}}"
/>
        </list>
    </property>
</bean>


On NetPartner login tab:

SSO: yes
Identity provider url: https:/myshibserver/idp/profile/SAML2/Redirect/SSO
Protocol binding: Post
Request nameid format: [Do Not Use]
Service Provider Name: NetPartner



Any help GREATLY appreciated.
-Norm Bodnar
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180517/f0c4b40f/attachment.html>


More information about the users mailing list