Azure AD and shibboleth IdP integration

Chris Phillips Chris.Phillips at canarie.ca
Mon Feb 1 15:13:24 UTC 2021


Hi Raja..

 

Matthew an David’s prior comments are on point:
Ensure you are releasing attributes from Azure in the Relying Party configuration in Azure (Trust Task 4)
David’s comment on  the unspecified item is what I encountered as well and why the Proxy Task 3 step is needed to ingest the Azure attributes as unspecified in nature
Increasing log level to DEBUG is a great instrument to better understand what’s happening there
 

That should reveal how well (or not) things flow and hopefully reveal next steps.

 

Note that the example in Proxy Task 3 is not exhaustive of all attributes you may want. You will likely need more definitions depending on what you require from Azure AD so expect to add more in that small set.

 

 

C.

 

 

From: "users-bounces at shibboleth.net" <users-bounces at shibboleth.net> on behalf of "Raja V, Scientist - C (CS)" <raja at inflibnet.ac.in>
Reply-To: SHIB-USERS <users at shibboleth.net>
Date: Monday, February 1, 2021 at 1:00 AM
To: SHIB-USERS <users at shibboleth.net>
Cc: Francis Jayakanth <Francis at iisc.ac.in>
Subject: Azure AD and shibboleth IdP integration

 

Hi,

We are trying to integrate Azure AD with shibboleth by following document available at https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+in+the+Shibboleth+IdP+to+connect+with+Azure+AD

 

However, after authentication, we are getting the following error. Can anyone help us out?

 

2021-02-01 11:21:53,314 - 10.0.7.6 - INFO [Shibboleth-Audit.SSO:282] - 10.0.7.6||2021-02-01T05:51:53.314018Z||https://sts.windows.net******/|_282b0ffa-9537-4b9c-9444-bbaf4bee7700|password|2021-02-01T04:42:10.204Z|azureObjectidentifier,azureIdentityprovider,azureGivenname,azureDisplayname,azureAuthnmethodsreferences,azureTenantid,azureEmailaddress,azureSurname|email@email.org|emailAddress||false||Redirect|POST||Success|||Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.104 Safari/537.36
2021-02-01 11:21:53,388 - 10.0.7.6 - ERROR [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:78] - Profile Action SelectSubjectCanonicalizationFlow: No potential flows left to choose from, canonicalization will fail
2021-02-01 11:21:53,390 - 10.0.7.6 - INFO [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:142] - Profile Action SelectAuthenticationFlow: Moving incomplete flow authn/SAML to intermediate set
2021-02-01 11:21:53,390 - 10.0.7.6 - INFO [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:316] - Profile Action SelectAuthenticationFlow: No potential flows left to choose from, authentication failed
                                                     

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210201/f857f5aa/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4340 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20210201/f857f5aa/attachment.p7s>


More information about the users mailing list