Error in Shibboleth login from mobile devices
Nate Klingenstein
ndk at signet.id
Tue Nov 26 14:38:49 EST 2019
Aseem,
The easiest way is with a tool like SAML tracer in Firefox or even just cURL on any Linux distribution. Our company has been busy and we have to help paying customers first. We should be able to look more closely into this this weekend.
I'm sorry it's taken me so long,
Nate.
On Nov 26, 2019 5:29 AM, Aseem Keskar <Aseem.Keskar at wns.com> wrote:
Hi Nate,
We have tried to find the HTTPS traffic details from the IdP server but unable to find this details.
Server Configuration
IdP Server – Unix OS and Jetty Server. (Unable to find the Https traffic details. Will the Jetty log will help here?)
SP Server – Windows R2 2016 and IIS web server
How can we find the exact HTTPS traffic / HTTP Request headers for working transaction and for failing transaction from the IdP server? Can you please provide some help here?
Thanks and Regards,
Aseem Keskar
Group Manager – IT - WNS Global Services (P) Ltd |www.wns.com <http://www.wns.com/>
Gate No 4, Plant 10 / 11 Godrej & Boyce Complex, Pirojshanagar, LBS MargVikhroli (West), Mumbai,Maharashtra,
IP: 67219|Direct: | Mobile: +919004427356 | Email :aseem.keskar at wns.com <mailto:aseem.keskar at wns.com>
ONE WNS ONE GOAL OUTPERFORM
--------------------------------
<http://www.linkedin.com/company/wns-global-services>
<http://twitter.com/wnsholdings>
<http://www.youtube.com/wnsglobalservices>
Connect with WNS
From: Nate Klingenstein <ndk at signet.id>
Sent: 16 November 2019 12:01
To: Aseem Keskar <Aseem.Keskar at wns.com>
Cc: Chetan Chaudhari <Chetan.Chaudhari at wns.com>; Rupesh Kale <Rupesh.Kale at wns.com>; Nilesh Raut <Nilesh.Raut at wns.com>; users at shibboleth.net; Jyoti Sawant <Jyoti.Sawant at wns.com>; Pravin Ingale <Pravin.Ingale at wns.com>
Subject: Re: Error in Shibboleth login from mobile devices
External Email: This email has not originated from WNS. Do not click on attachment or links/URL unless sender is reliable. Malware/ Viruses can be easily transmitted via email and also lead to a Phishing compromise.
Pardon me, that should read from the Shibboleth server, e.g. IdP. Either end should be able to display the raw traffic.
Sorry. Internet outage here and I'm ironically bad with phones.
On Nov 15, 2019 10:19 PM, Nate Klingenstein <ndk at signet.id <mailto:ndk at signet.id> > wrote:
Aseem,
Strictly speaking, that means the IdP was attempting to continue some flow(usually login) but was unable to do so. It's usually the back button, but that's obviously unlikely here.
I would like an example of the HTTPS traffic on a working transaction and an example of a failing transaction. All you really know from the the server side is that it's trying to continue a webflow that is invalid.
This could be a hard fix, depending on what's happening.
Take care,
Nate.
On Nov 15, 2019 8:46 PM, Aseem Keskar <Aseem.Keskar at wns.com <mailto:Aseem.Keskar at wns.com> > wrote:
Hello Team,
We have implemented Shibboleth SSO login in our mobile application. Our mobile application has been built on IONIC3.
We are frequently facing issue on Shibboleth login for mobile devices where sometime it redirects to error (find the attached error screenshots) and sometime it works fine without any error. Shibboleth login for mobile device is not working consistently.
We are facing this issue in iOS device more frequently (this error appears 1 or 2 times out of 4-5 login attempts). For Android device, it is not coming so frequently like iOS (for Android error appears 1 or 2 times out of 14-15 login attempts).
We found the following error in the log file from IdP server.
[net.shibboleth.ext.spring.error.ExtendedMappingExceptionResolver:136] - Resolved [org.springframework.webflow.execution.repository.NoSuchFlowExecutionException: No flow execution could be found with key 'e1s2' -- perhaps this executing flow has ended or expired? This could happen if your users are relying on browser history (typically via the back button) that references ended flows.] to ModelAndView: reference to view with name 'error'.
Kindly help us to find root cause of this error and provide some solution for the same?
Thanks and regards,
Aseem Keskar--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net <mailto:users-unsubscribe at shibboleth.net>
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net <mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20191126/1299b353/attachment.html>
More information about the users
mailing list