OIDC OP No client information returned for https://redacted.csu.edu.au/oidc
Lipscomb, Gary
glipscomb at csu.edu.au
Thu May 6 03:30:50 UTC 2021
Hi,
I'm doing a clean install of IDP 4.1 and the plugins OIDC OP and OIDCCommon.
I'm using a SAML metadata.xml file for the OIDC client.
When I access the site I'm seeing the below in the logs
2021-05-06 13:07:15,600 - 10.0.2.2 - INFO [net.shibboleth.idp.plugin.oidc.op.profile.impl.OIDCMetadataLookupHandler:110] - Message Handler: No client information returned for https://redacted.csu.edu.au/oidc
This appears before I enter my credentials on the login page. After login I can access the site OK.
If this INFO message just that or have I missed a configuration item?
Regards
Gary
2021-05-06 13:07:15,598 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.decoding.impl.OIDCAuthenticationRequestDecoder:49] - Inbound request GET
Headers:
accept:[text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8]
accept-encoding:[gzip, deflate, br]
accept-language:[en-US,en;q=0.5]
connection:[keep-alive]
Content-Type:[null]
DNT:[1]
host:[idpdev.csu.edu.au]
Upgrade-Insecure-Requests:[1]
user-agent:[Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0]
Parameters:
scope:openid profile rememberMe email
response_type:id_token
redirect_uri:https://redacted.csu.edu.au/Redacted/Authenticate/OpenID/signin-custom
state:OpenIdConnect.AuthenticationProperties=REDACTED
nonce:REDACTED
client_id:https://redacted.csu.edu.au/oidc
response_mode:form_post
2021-05-06 13:07:15,599 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.decoding.impl.OIDCAuthenticationRequestDecoder:56] - Decoded inbound request query string scope=openid+profile+rememberMe+email&response_type=id_token&redirect_uri=https%3A%2F%2Fredacted.csu.edu.au%2FRedacted%2FAuthenticate%2FOpenID%2Fsignin-custom&state=OpenIdConnect.AuthenticationProperties%3DREDACTED&nonce=REDACTED&client_id=https%3A%2F%2Fredacted.csu.edu.au%2Foidc&response_mode=form_post
2021-05-06 13:07:15,600 - 10.0.2.2 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:169] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'net.shibboleth.idp.plugin.oidc.op.profile.impl.OIDCMetadataLookupHandler' on INBOUND message context
2021-05-06 13:07:15,600 - 10.0.2.2 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'com.nimbusds.openid.connect.sdk.AuthenticationRequest'
2021-05-06 13:07:15,600 - 10.0.2.2 - INFO [net.shibboleth.idp.plugin.oidc.op.profile.impl.OIDCMetadataLookupHandler:110] - Message Handler: No client information returned for https://redacted.csu.edu.au/oidc
2021-05-06 13:07:15,601 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.InitializeRelyingPartyContext:142] - Attaching RelyingPartyContext for rp https://redacted.csu.edu.au/oidc
2021-05-06 13:07:15,603 - 10.0.2.2 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:169] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLProtocolAndRoleHandler' on INBOUND message context
2021-05-06 13:07:15,603 - 10.0.2.2 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'com.nimbusds.openid.connect.sdk.AuthenticationRequest'
2021-05-06 13:07:15,603 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.SetEntityIdToSAMLPeerEntityContext:99] - Profile Action SetEntityIdToSAMLPeerEntityContext: Set clientID 'https://redacted.csu.edu.au/oidc' to the peer entity context
2021-05-06 13:07:15,644 - 10.0.2.2 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:169] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler' on INBOUND message context
2021-05-06 13:07:15,644 - 10.0.2.2 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'com.nimbusds.openid.connect.sdk.AuthenticationRequest'
2021-05-06 13:07:15,646 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCMetadataContext:109] - Profile Action PopulateOIDCMetadataContext: Client information found and attached.
2021-05-06 13:07:15,646 - 10.0.2.2 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeRelyingPartyContextFromSAMLPeer:131] - Profile Action InitializeRelyingPartyContextFromSAMLPeer: Attaching RelyingPartyContext based on SAML peer https://redacted.csu.edu.au/oidc
2021-05-06 13:07:15,647 - 10.0.2.2 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:249] - Resolving relying party configuration
2021-05-06 13:07:15,647 - 10.0.2.2 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:261] - Checking if relying party configuration EntityNames[https://shib.pebblepad.co.uk/shibboleth-sp,https://PlaceH0lder.csu.edu.au/shibboleth,] is applicable
2021-05-06 13:07:15,647 - 10.0.2.2 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:266] - Relying party configuration EntityNames[https://shib.pebblepad.co.uk/shibboleth-sp,https://PlaceH0lder.csu.edu.au/shibboleth,] is not applicable
2021-05-06 13:07:15,647 - 10.0.2.2 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:261] - Checking if relying party configuration csu.NoUserConsentRelyingPartybyTag is applicable
2021-05-06 13:07:15,650 - 10.0.2.2 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:266] - Relying party configuration csu.NoUserConsentRelyingPartybyTag is not applicable
2021-05-06 13:07:15,650 - 10.0.2.2 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:269] - No relying party configurations are applicable, returning the default configuration shibboleth.DefaultRelyingParty
2021-05-06 13:07:15,650 - 10.0.2.2 - DEBUG [net.shibboleth.idp.profile.impl.SelectRelyingPartyConfiguration:136] - Profile Action SelectRelyingPartyConfiguration: Found relying party configuration shibboleth.DefaultRelyingParty for request
2021-05-06 13:07:15,651 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractInitializeOutboundResponseMessageContext:48] - Profile Action InitializeOutboundAuthenticationResponseMessageContext: Initialized outbound message context
2021-05-06 13:07:15,652 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.InitializeOutboundAuthenticationResponseMessageContext:238] - Profile Action InitializeOutboundAuthenticationResponseMessageContext: SAML metadata context already found
2021-05-06 13:07:15,653 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.SetRequestObjectToResponseContext:110] - Profile Action SetRequestObjectToResponseContext: No request_uri or request by value, nothing to do
2021-05-06 13:07:15,654 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCEncryptionParameters:186] - Profile Action PopulateOIDCEncryptionParameters: Resolving EncryptionParameters for request, purpose request object decryption
2021-05-06 13:07:15,656 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCEncryptionParameters:242] - Profile Action PopulateOIDCEncryptionParameters: Adding oidc client information to resolution criteria for key transport/encryption algorithms
2021-05-06 13:07:15,656 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.security.impl.OIDCClientInformationEncryptionParametersResolver:227] - No algorithm information in client information, nothing to do
2021-05-06 13:07:15,656 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCEncryptionParameters:201] - Profile Action PopulateOIDCEncryptionParameters: Resolved EncryptionParameters for request object decryption
2021-05-06 13:07:15,659 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCSignatureSigningParameters:212] - Profile Action PopulateOIDCSignatureSigningParameters: Signing enabled
2021-05-06 13:07:15,659 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCSignatureSigningParametersHandler:208] - Message Handler: Signing enabled
2021-05-06 13:07:15,659 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCSignatureSigningParametersHandler:221] - Message Handler: Resolving SignatureSigningParameters for request
2021-05-06 13:07:15,659 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCSignatureSigningParametersHandler:258] - Message Handler: Adding oidc client information to resolution criteria for signing/digest algorithms
2021-05-06 13:07:15,659 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.security.impl.OIDCClientInformationSignatureValidationParametersResolver:186] - Resolving SignatureSigningParameters, purpose request object signature validation
2021-05-06 13:07:15,659 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.security.impl.OIDCClientInformationSignatureValidationParametersResolver:219] - No client secret to use as a key
2021-05-06 13:07:15,660 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.security.impl.OIDCClientInformationSignatureValidationParametersResolver:240] - No keyset available
2021-05-06 13:07:15,660 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.security.impl.OIDCClientInformationSignatureValidationParametersResolver:271] - Not able to resolve signature validation credential based on provided client information
2021-05-06 13:07:15,660 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.security.impl.OIDCClientInformationSignatureValidationParametersResolver:298] - Validation failure: Unable to resolve signature validation credential
2021-05-06 13:07:15,660 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCSignatureSigningParametersHandler:274] - Message Handler: Failed to resolve SignatureSigningParameters
2021-05-06 13:07:15,661 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.DecryptRequestObject:102] - Profile Action DecryptRequestObject: No request object, nothing to do
2021-05-06 13:07:15,661 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.ValidateRequestObject:91] - Profile Action ValidateRequestObject: No request object, nothing to do
2021-05-06 13:07:15,662 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.ValidateRedirectURI:101] - Profile Action ValidateRedirectURI: Redirection URI validated https://redacted.csu.edu.au/Redacted/Authenticate/OpenID/signin-custom
2021-05-06 13:07:15,663 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.SetRequestedSubjectToResponseContext:66] - Profile Action SetRequestedSubjectToResponseContext: No requested claims nor id token hint, nothing to do
2021-05-06 13:07:15,665 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCSignatureSigningParameters:212] - Profile Action PopulateOIDCSignatureSigningParameters: Signing enabled
2021-05-06 13:07:15,665 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCSignatureSigningParametersHandler:208] - Message Handler: Signing enabled
2021-05-06 13:07:15,665 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCSignatureSigningParametersHandler:221] - Message Handler: Resolving SignatureSigningParameters for request
2021-05-06 13:07:15,665 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCSignatureSigningParametersHandler:258] - Message Handler: Adding oidc client information to resolution criteria for signing/digest algorithms
2021-05-06 13:07:15,665 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.security.impl.OIDCClientInformationSignatureSigningParametersResolver:137] - Resolving SignatureSigningParameters, purpose id token signing
2021-05-06 13:07:15,666 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCSignatureSigningParametersHandler:274] - Message Handler: Resolved SignatureSigningParameters
2021-05-06 13:07:15,666 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCEncryptionParameters:186] - Profile Action PopulateOIDCEncryptionParameters: Resolving EncryptionParameters for request, purpose response encryption
2021-05-06 13:07:15,667 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCEncryptionParameters:242] - Profile Action PopulateOIDCEncryptionParameters: Adding oidc client information to resolution criteria for key transport/encryption algorithms
2021-05-06 13:07:15,667 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.security.impl.OIDCClientInformationEncryptionParametersResolver:227] - No algorithm information in client information, nothing to do
2021-05-06 13:07:15,667 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCEncryptionParameters:201] - Profile Action PopulateOIDCEncryptionParameters: Failed to resolve EncryptionParameters for response encryption
2021-05-06 13:07:15,667 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCEncryptionParameters:217] - Profile Action PopulateOIDCEncryptionParameters: Encryption optional
2021-05-06 13:07:16,429 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.InitializeAuthenticationContext:106] - Profile Action InitializeAuthenticationContext: Initializing authentication context
2021-05-06 13:07:16,430 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.InitializeAuthenticationContext:127] - Profile Action InitializeAuthenticationContext: Created authentication context: AuthenticationContext{initiationInstant=2021-05-06T03:07:16.430207Z, isPassive=false, forceAuthn=false, requiredName=null, hintedName=null, maxAge=null, potentialFlows=[], activeResults=[], attemptedFlow=null, signaledFlowId=null, authenticationStateMap={}, resultCacheable=true, authenticationResult=null, completionInstant=null}
2021-05-06 13:07:16,430 - 10.0.2.2 - DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.ProcessRequestedAuthnContext:135] - No acr values nor acr claim values in request, nothing to do
2021-05-06 13:07:16,432 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:215] - Profile Action PopulateAuthenticationContext: Installed 1 potential authentication flows into AuthenticationContext
2021-05-06 13:07:16,433 - 10.0.2.2 - DEBUG [net.shibboleth.idp.session.impl.PopulateSessionContext:130] - Profile Action PopulateSessionContext: No session found for client
2021-05-06 13:07:16,436 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.InitializeRequestedPrincipalContext:152] - Profile Action InitializeRequestedPrincipalContext: Profile configuration did not supply any default authentication methods
2021-05-06 13:07:16,436 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByForcedAuthn:57] - Profile Action FilterFlowsByForcedAuthn: Request does not have forced authentication requirement, nothing to do
2021-05-06 13:07:16,436 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:57] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do
2021-05-06 13:07:16,437 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:274] - Profile Action SelectAuthenticationFlow: No specific Principals requested
2021-05-06 13:07:16,437 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:312] - Profile Action SelectAuthenticationFlow: No usable active results available, selecting an inactive flow
2021-05-06 13:07:16,437 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:369] - Profile Action SelectAuthenticationFlow: Selecting inactive authentication flow authn/MFA
2021-05-06 13:07:16,438 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.PopulateMultiFactorAuthenticationContext:167] - Profile Action PopulateMultiFactorAuthenticationContext: No active results extracted
2021-05-06 13:07:16,439 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:212] - Profile Action TransitionMultiFactorAuthentication: Applying MFA transition rule to determine initial state
2021-05-06 13:07:16,439 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:226] - Profile Action TransitionMultiFactorAuthentication: MFA flow transition after 'proceed' event to 'authn/Password' flow
2021-05-06 13:07:16,440 - 10.0.2.2 - DEBUG [net.shibboleth.idp.authn.impl.ExtractUsernamePasswordFromBasicAuth:116] - Profile Action ExtractUsernamePasswordFromBasicAuth: No appropriate Authorization header found
2021-05-06 13:07:16,454 - 10.0.2.2 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:570] - Found Name 'REDACTED PortalConnect - DEVEL' for Locale 'en'
| ALBURY-WODONGA | BATHURST | BRISBANE | CANBERRA | DUBBO | GOULBURN | MELBOURNE | ORANGE | PORT MACQUARIE | SYDNEY | WAGGA WAGGA |
LEGAL NOTICE
This email (and any attachment) is confidential and is intended for the use of the addressee(s) only. If you are not the intended recipient of this email, you must not copy, distribute, take any action in reliance on it or disclose it to anyone. Any confidentiality is not waived or lost by reason of mistaken delivery. Email should be checked for viruses and defects before opening. Charles Sturt University does not accept liability for viruses or any consequence which arise as a result of this email transmission. Email communications with Charles Sturt University may be subject to automated email filtering, which could result in the delay or deletion of a legitimate email before it is read at Charles Sturt University. The views expressed in this email are not necessarily those of Charles Sturt University.
Charles Sturt University in Australia The Grange Chancellery, Panorama Avenue, Bathurst NSW Australia 2795 (ABN: 83 878 708 551; CRICOS Provider Number: 00005F (National)). TEQSA Provider Number: PV12018
Consider the environment before printing this email.
More information about the users
mailing list