Webisoget not happy with our V4 IdP

Wessel, Keith kwessel at illinois.edu
Wed Feb 10 20:47:00 UTC 2021


Hi, all,

Hoping to get some direction from folks here between the UW folks who wrote Webisoget and the Shib team.

We've had a Nagios check of our IdP running for several years that uses Webisoget. For some reason, it doesn't like our V4 IdP in Aws. I'm trying to determine if it's something that's changed in V4's login flow or something with how Webisoget is interacting with the Amazon application load balancer and containerized IdP behind it.

Webisoget is getting redirected to the login page, but instead of getting the login page back, it's getting an error. The log shows the MFA flow using authn/password:

2021-02-10 13:01:39,862 - DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:226] - Profile Action TransitionMultiFactorAuthentication: MFA flow transition after 'proceed' event to 'authn/Password' flow

The password flow looks for an authentication header:

2021-02-10 13:01:39,863 - DEBUG [net.shibboleth.idp.authn.impl.ExtractUsernamePasswordFromBasicAuth:116] - Profile Action ExtractUsernamePasswordFromBasicAuth: No appropriate Authorization header found

Then the very next log message is a state exception:

2021-02-10 13:01:39,903 - ERROR [org.springframework.webflow.execution.repository.NoSuchFlowExecutionException:74]

Any theories why this might be happening when it doesn't happen with our on-prem V3 IdP?

UW folks, if it helps, we're on an older version of Webisoget: 2.8.0. Has anything changed in newer versions that might have fixed a problem like this?

Thanks,
Keith




More information about the users mailing list