SP Cert expiration log

vadud3 at gmail.com vadud3 at gmail.com
Wed Jul 14 14:50:31 UTC 2021


When I try to login to node1.server.com, it redirects me to login page of
server.example.com. Here are the steps. Not sure how to troubleshoot this.

I first try to login to node1 page

https://node1.example.org/jira


It takes me to signon page

https://server.example.org/shibboleth-ds/index.html?entityID=https://node1.example.org&return=https://node1.example.org/Shibboleth.sso/Login?SAMLDS=1&target=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3


I click on signon button which links to below

https://server.example.org/Shibboleth.sso/Login?SAMLDS=1&target=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3&entityID=http://ssotest.example.org/adfs/services/trust


On the chrome Network console I see the samlrequest

https://ssotest.example.org/adfs/ls/?SAMLRequest=....&RelayState=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3&SigAlg=http://www.w3.org/2001/04/xmldsig-more#rsa-sha256&Signature=f3esrxiTFWYxo2KDSsNBdXAADsQ/YBhohzY8z6x3PTtETpc7gl0VviXNwAEpcLp7LitGfd82nqiNU32E/nUWVnO37fJGyuUFnaAIhQcXeGxI6nGTy+HWiCouuVDgdMXrzvf/M5K7rS3cw1tbOoGPAeiEUv8xh5aR1v6c0XjUTno9ZC2ERo7OtEhPA6F/sCdK4e0eGnx0RCop2PLdVdeprPk25gczGjBwhKxsx3wxFeqRU/OqMepmFLB3SBqXXRaEy1ekyE0Hqb9axYhdJqn85j9Dl3eOpkKwabZdjDF010GYy4p2vJo3qzu+RB+N8NL75XXbWn3Q==


SAMLRequest is

<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
> AssertionConsumerServiceURL="
> https://server.example.org/Shibboleth.sso/SAML2/POST"
> Destination="https://ssotest.example.org/adfs/ls/"
> ID="_dafedbb9424fd98c192d040ba9833"
> IssueInstant="2021-07-14T14:11:00Z"
> ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
> Version="2.0">
> <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
> https://server.example.org
> </saml:Issuer>
> <samlp:NameIDPolicy AllowCreate="1"/>

</samlp:AuthnRequest>


Then takes me back to the login page of the server. So login to node1 never
worked. The next three steps on Network console are

GET https://ssotest.example.org/favicon.ico
> POST https://server.example.org/Shibboleth.sso/SAML2/POST
> GET https://server.example.org/


I am kind a lost. Any suggestion on what is going on and how to
troubleshoot this?

Thanks,
Asif






On Thu, Jul 8, 2021 at 4:04 AM Alan Buxey via users <users at shibboleth.net>
wrote:

> hi,
>
> > We recently got into a situation where our SP cert expired and we only
> found out the next morning when everyone was trying to login, yikes! We
> remedy the situation and monitoring the cert.
>
>
> your Shibboleth/SAML cert expired, or your service cert
> (apache/IIS/whatever) cert expired?
>
> in terms of monitoring, know when your cert expires, you don't want to
> only know when logs are showing you its expired.  stick expiry dates
> in calendars AND run a monitoring tool that checks your certificate
> expiry dates on public services (eg a NAGIOS plugin etc)
>
> alan
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>


-- 
Asif Iqbal
PGP Key: 0xE62693C5 KeyServer: pgp.mit.edu
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210714/d2cd1853/attachment.htm>


More information about the users mailing list