IDP v 4 on Windows No Apache
Rick Hoodenpyle
rhoodenpyle at rms-inc.com
Tue Jul 19 06:21:20 UTC 2022
I have gotten my IDP v 4 on Windows installed. From my website I get
redirected to the IDP login, I login and in the IDP logs I am told I was
successful in logging in and in the SP logs I am told a new session was
created. However, no server variables appear to be getting sent over to the
site covered by the SP.
Here are example log entries:
IDP
2022-07-19 01:50:11,978 - 192.168.0.241 - INFO
[org.ldaptive.auth.Authenticator:291] - Authentication succeeded for dn:
cn={USERNAME},ou=users,dc={DOMAIN},dc=com
2022-07-19 01:50:11,979 - 192.168.0.241 - INFO
[net.shibboleth.idp.authn.impl.LDAPCredentialValidator:163] - Credential
Validator ldap: Login by '{USERNAME}' succeeded
2022-07-19 01:50:12,082 - 192.168.0.241 - INFO
[net.shibboleth.idp.authn.impl.FinalizeAuthentication:196] - Profile Action
FinalizeAuthentication: Principal {USERNAME} authenticated
2022-07-19 01:50:12,824 - 192.168.0.241 - INFO [Shibboleth-Audit.SSO:283] -
192.168.0.241|2022-07-19T05:49:55.952513100Z|2022-07-19T05:50:12.824587100Z|{USERNAME}|
https://SERVER.DOMAIN.com/shibboleth|_20a8c0dfeded5d513a5b745918d7d84b|password|2022-07-19T05:50:11.984575300Z||AAdzZWNyZXQxSsAEcIp4H7CMeAnwlsZMPKe0D/m4l5/kJ7oym+ZQ9HRN6B70d24bJO6Kj3MOvOGFvicM7lJkYqsNs66Z0GcelKW3qFaG9+d4Ft0TUakoMhSQPiy3/TZ+n+BUbVxSRW/EOqGaken9lWRLPvwak3U=|transient|false|false|AES128-GCM|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST||Success||0f15b2d6cac986a462530f8987bfe9d26b6db1d421989b2820153d9a82a8ad3e|Mozilla/5.0
(Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
103.0.0.0 Safari/537.36
Then in the logs come several of the below warnings.
2022-07-19 01:54:57,060 - - WARN
[org.ldaptive.pool.BlockingConnectionPool:784] -
org.ldaptive.pool.AbstractConnectionPool$DefaultPooledConnectionProxy at 1a304bf1
failed validation
In the SP logs I get the following:
2022-07-19 01:57:16|Shibboleth-TRANSACTION.AuthnRequest|||
https://idp2.DOMAIN.com/idp||||||urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect||||||
2022-07-19
01:57:17|Shibboleth-TRANSACTION.Login||_3a26d8595cc9dfd6573e352adb7d033e|
https://SERVER.DOMAIN.com/idp|_c42b02ef868fd1042f809e99e2943e75|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|2022-07-19T01:50:11||AAdzZWNyZXQxR3rg6Ap2AVPSQCcAuYpQr+rWsBVf81feDLYQWwcGY4DiIU+0Dbm6ECRfIaHm0Srq1iAcTmy5AZBxMWDrrCBk+/1AlUFDVUY76W9fnnqR12Ft9t8uzy6XVEWdeEh0gNsJnwaw/C5lag0Ew0PyRQA=|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST||urn:oasis:names:tc:SAML:2.0:status:Success|||Mozilla/5.0
(Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
103.0.0.0 Safari/537.36|IP
AND
2022-07-19 01:57:17 INFO Shibboleth.SessionCache [1] [default]: new session
created: ID (_3a26d8595cc9dfd6573e352adb7d033e) IdP (
https://idp2.DOMAIN.com/idp) Protocol(urn:oasis:names:tc:SAML:2.0:protocol)
Address (IP)
On the website I get the following:
Invalid User login attempt via Shibboleth. No value found in Server
Variables for: givenName
And if I look at the session it gives me no variables. I do have the
<Handler type="Session" Location="/Session" showAttributeValues="true"/>
entry in the Shibboleth2.xml file on the SP.
*Miscellaneous*
*Session Expiration (barring inactivity):* 477 minute(s)
*Client Address:* 192.168.0.241
*SSO Protocol:* urn:oasis:names:tc:SAML:2.0:protocol
*Identity Provider:* https://idp2.DOMAIN.com/idp
*Authentication Time:* 2022-07-19T06:17:54.822Z
*Authentication Context Class:*
urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
*Authentication Context Decl:* (none)
*Attributes*
Any help would be appreciated.
Cheers,
Rick
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220719/052a7cf9/attachment.htm>
More information about the users
mailing list