Azure AD and shibboleth IdP integration
Matthew Slowe
Matthew.Slowe at jisc.ac.uk
Mon Feb 1 10:52:56 UTC 2021
> On 1 Feb 2021, at 06:00, Raja V, Scientist - C (CS) <raja at inflibnet.ac.in> wrote:
>
> Hi,
> We are trying to integrate Azure AD with shibboleth by following document available at https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+in+the+Shibboleth+IdP+to+connect+with+Azure+AD
>
> However, after authentication, we are getting the following error. Can anyone help us out?
>
> ...snip...
> [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:316] - Profile Action SelectAuthenticationFlow: No potential flows left to choose from, authentication failed
Hi,
At a guess, you're not getting the attribute you expect either because it's not mapped correctly (Proxy Task 3) or the Attribute Filter isn't allowing the incoming attributes in the filter through (Proxy Task 2).
It's probably worth turning up the logging to DEBUG and following it through looking for where the attributes either aren't found or are filtered out.
I might be wrong though!
--
Matthew Slowe (GPG: 0x6BE0CF7D04600314)
Senior Technical Consultant and Support specialist - Trust & Identity, Jisc
Team: 0300 300 2212, option 2
Lumen House, Library Avenue, Harwell Oxford, Didcot, OX11 0SG
More information about the users
mailing list