idp 3.4 CAS proxy authentication fails

Mathis, Bradley bmathis at pima.edu
Thu Oct 25 18:09:23 EDT 2018


I'm testing out an upgrade from idp 3.3 to 3.4.

Our stage portal login uses CAS and appears to be doing proxy
authentication.  My other CAS apps are working Logging in OK.  Here's a
snippet from the idp-process log.

2018-10-25 12:23:00,697 - INFO
[net.shibboleth.idp.cas.flow.impl.ValidateTicketAction:117] - Successfully
validated
ST-AADXGZLDOJSXIMN4JSUQLLELYJCFENW63UKXJQVCR7X437TCIKAFSEBAFVQTBVCV42DN2HHWRIBOWNHAKKA4GJHY3J4U4IIFV32MS4MKXATA7NCICPZMPZXUF6M726SA6IEKNJ4PID7MTZ4LG4JG37WK5BTZXX3TY26RTXMMVE5LOWYWWT32R7KPP57ZJ24OW44PV6X2UFG6XUEBIO3IDMY7A3S4R5F54525AKMXQS7DOHLACUFZILQMITGREHTCZT5573U6UY23VS6AQ43X5PTLVGLTBWKR27Q37KH3OURAK2TBJRFH4CEOQWPPPBB6WD72HTMPM3IK4726BS3ISDPJPV46RWYB5CQR2RS2UZUMCKL7T5I5562ZSZ4DC4MXID5PU5XJ
for https://mypima-stage.pima.edu/c/portal/login
2018-10-25 12:23:00,701 - DEBUG
[net.shibboleth.idp.cas.flow.impl.ValidateProxyCallbackAction:129] -
Attempting proxy authentication to
https://mypima-stage.pima.edu/recievePgt?pgtId=PGT-1540495380698-RMCKp3kwimB1hlgOaRCyiYRxmXqy2pROacKMe4DrsxQvCDWQae&pgtIou=PGTIOU-1540495380698-MiZoaBIdxDJEkg0hC7phA0PbBgCqGdyKLW7SDXoHQgjBn4XZek
2018-10-25 12:23:00,701 - INFO
[net.shibboleth.idp.cas.flow.impl.ValidateProxyCallbackAction:139] - Proxy
authentication failed for https://mypima-stage.pima.edu/recievePgt:
java.lang.IllegalStateException: Service context not found in profile
request context as required
2018-10-25 12:23:00,728 - WARN
[org.opensaml.profile.action.impl.LogEvent:105] - A non-proceed event
occurred while processing the request: ProxyCallbackAuthenticationFailure


Note: this login worked under idp 3.3 without any special configuration
(uh..at least I don't see or recall anything special that I did before).
I have set this up using the both services defined in the cas-protocol.xml
and using the CASMetadataProfile. (not at the same time of course)  Both
Configurations give me the the same error.  I'm currently configured
using CASMetadataProfile.


I have read through the following documentation.


https://wiki.shibboleth.net/confluence/display/IDP30/CASProxyAuthenticatorDeprecation

https://wiki.shibboleth.net/confluence/display/IDP30/CASServiceSAMLMetadata

<goog_1627042315>
https://wiki.shibboleth.net/confluence/display/SC/CASMetadataProfile

https://wiki.shibboleth.net/confluence/display/IDP30/CASProxyPKIXTrustSimple




Any ideas on what might be wrong are appreciated.   This is not production
so it's not critical yet.. but I'm going to have to cross this bridge one
day.




Brad Mathis
Principal Systems Analyst
Pima Community College
IT - Technical Services
520.206.4826
bmathis at pima.edu
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181025/02953a4c/attachment.html>


More information about the users mailing list