Multiple DuoOIDC -- Integration-Specific Principal Sets
Schwendner, Joanne
joanne_schwendner at brown.edu
Fri Sep 20 10:12:04 UTC 2024
Thanks very much...
On the chance it might be something obvious, here is what I am seeing.
(otherwise, I'll open a ticket)
I first log in to the normal SP. Password ok. It then goes to the
DefaultDuoOIDC Duo and is approved, with the default principal '
https://refeds.org/profile/mfa'. Good.
Then I try to SSO to the Special SP, which should decide to use the
Level2DuoOIDC 'https://refeds.org/profile/mfa-level2' and go to Duo
again. But it fails instead.
The IDP first says the result from the DefaultDuo is not usable:
"Active result for flow authn/MFA not usable, ignoring."
But then it says it's reusing it:
"Reusing active result for flow authn/DuoOIDC"
And then says it doesn't satisfy the request:
"Authentication result for flow authn/MFA did not satisfy the request"
*Here is the log from the SSO:*
DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] -
Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on
message context containing a message of type
'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl' -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.saml.profile.impl.InitializeAuthenticationContext:239]
- Profile Action InitializeAuthenticationContext: AuthnRequest did not
contain Scoping, nothing to do - [node01uk2mhrhajtpqir5jq8wum6273] -
[99.99.99.99]
DEBUG
[net.shibboleth.idp.saml.profile.impl.InitializeAuthenticationContext:222]
- Profile Action InitializeAuthenticationContext: Created authentication
context:
AuthenticationContext{initiationInstant=2024-09-19T21:59:02.124556Z,
isPassive=false, forceAuthn=false, requiredName=null, hintedName=null,
maxAge=null, potentialFlows=[], activeResults=[], attemptedFlow=null,
signaledFlowId=null, authenticationStateMap={}, resultCacheable=true,
authenticationResult=null, completionInstant=null} -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.saml.saml2.profile.impl.ProcessRequestedAuthnContext:167]
- Profile Action ProcessRequestedAuthnContext: AuthnRequest did not contain
a RequestedAuthnContext, nothing to do - [node01uk2mhrhajtpqir5jq8wum6273]
- [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:213] -
Profile Action PopulateAuthenticationContext: Installed 1 potential
authentication flows into AuthenticationContext -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.session.impl.StorageBackedSessionManager:813] -
Performing primary lookup on session ID
94a4c1e8119de287fef5a4a7cec473673631807bc0b0331b5f87f6a8e2de240d -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.session.impl.StorageBackedIdPSession:88] -
Updating expiration of primary record for session
94a4c1e8119de287fef5a4a7cec473673631807bc0b0331b5f87f6a8e2de240d to
2024-09-20T06:59:02.128223Z - [node01uk2mhrhajtpqir5jq8wum6273] -
[99.99.99.99]
DEBUG [net.shibboleth.idp.session.impl.StorageBackedIdPSession:540] -
Loading AuthenticationResult for flow authn/MFA in session
94a4c1e8119de287fef5a4a7cec473673631807bc0b0331b5f87f6a8e2de240d -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.session.impl.ExtractActiveAuthenticationResults:134] -
Profile Action ExtractActiveAuthenticationResults: Authentication result
authn/MFA is active, copying from session -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.InitializeRequestedPrincipalContext:163] -
Profile Action InitializeRequestedPrincipalContext: Established
RequestedPrincipalContext with 1 methods -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByForcedAuthn:57] - Profile
Action FilterFlowsByForcedAuthn: Request does not have forced
authentication requirement, nothing to do -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:57] -
Profile Action FilterFlowsByNonBrowserSupport: Request does not have
non-browser requirement, nothing to do - [node01uk2mhrhajtpqir5jq8wum6273]
- [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:401] -
Profile Action SelectAuthenticationFlow: Specific principals requested with
'exact' operator: [AuthnContextClassRefPrincipal{authnContextClassRef=
https://refeds.org/profile/mfa-level2}] - [node01uk2mhrhajtpqir5jq8wum6273]
- [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:511] -
Profile Action SelectAuthenticationFlow: Checking for an inactive flow or
active result compatible with operator 'exact' and principal '
https://refeds.org/profile/mfa-level2' - [node01uk2mhrhajtpqir5jq8wum6273]
- [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.principal.PrincipalEvalPredicateFactoryRegistry:126]
- Registry located predicate factory of type
'net.shibboleth.idp.authn.principal.impl.ExactPrincipalEvalPredicateFactory'
for principal type 'class
net.shibboleth.idp.saml.authn.principal.AuthnContextClassRefPrincipal' and
operator 'exact' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:526] -
Profile Action SelectAuthenticationFlow: Active result for flow authn/MFA
not usable, ignoring - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:369] -
Profile Action SelectAuthenticationFlow: Selecting inactive authentication
flow authn/MFA - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.PopulateMultiFactorAuthenticationContext:163]
- Profile Action PopulateMultiFactorAuthenticationContext: 2 active
result(s) extracted for possible reuse: [authn/Password, authn/DuoOIDC] -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:212] -
Profile Action TransitionMultiFactorAuthentication: Applying MFA transition
rule to determine initial state - [node01uk2mhrhajtpqir5jq8wum6273] -
[99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:226] -
Profile Action TransitionMultiFactorAuthentication: MFA flow transition
after 'proceed' event to 'authn/Password' flow -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:276] -
Profile Action TransitionMultiFactorAuthentication: Reusing active result
for flow authn/Password - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:214] -
Profile Action TransitionMultiFactorAuthentication: Applying MFA transition
rule to exit state 'authn/Password' - [node01uk2mhrhajtpqir5jq8wum6273] -
[99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.principal.PrincipalEvalPredicateFactoryRegistry:126]
- Registry located predicate factory of type
'net.shibboleth.idp.authn.principal.impl.ExactPrincipalEvalPredicateFactory'
for principal type 'class
net.shibboleth.idp.saml.authn.principal.AuthnContextClassRefPrincipal' and
operator 'exact' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.principal.PrincipalEvalPredicateFactoryRegistry:126]
- Registry located predicate factory of type
'net.shibboleth.idp.authn.principal.impl.ExactPrincipalEvalPredicateFactory'
for principal type 'class
net.shibboleth.idp.saml.authn.principal.AuthnContextClassRefPrincipal' and
operator 'exact' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:226] -
Profile Action TransitionMultiFactorAuthentication: MFA flow transition
after 'proceed' event to 'authn/DuoOIDC' flow -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:276] -
Profile Action TransitionMultiFactorAuthentication: Reusing active result
for flow authn/DuoOIDC - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:214] -
Profile Action TransitionMultiFactorAuthentication: Applying MFA transition
rule to exit state 'authn/DuoOIDC' - [node01uk2mhrhajtpqir5jq8wum6273] -
[99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:231] -
Profile Action TransitionMultiFactorAuthentication: MFA flow completing
with event 'proceed' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.FinalizeMultiFactorAuthentication:192]
- Profile Action FinalizeMultiFactorAuthentication: MFA complete, producing
merged result - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.impl.PopulateSubjectCanonicalizationContext:75] -
Profile Action PopulateSubjectCanonicalizationContext: Installing 2
canonicalization flows into SubjectCanonicalizationContext -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:100]
- Profile Action SelectSubjectCanonicalizationFlow: Checking
canonicalization flow c14n/x500 for applicability... -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:106]
- Profile Action SelectSubjectCanonicalizationFlow: Canonicalization flow
c14n/x500 was not applicable: Neither a single X509Certificate nor
X500Principal were found - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:100]
- Profile Action SelectSubjectCanonicalizationFlow: Checking
canonicalization flow c14n/simple for applicability... -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:83]
- Profile Action SelectSubjectCanonicalizationFlow: Selecting
canonicalization flow c14n/simple - [node01uk2mhrhajtpqir5jq8wum6273] -
[99.99.99.99]
DEBUG [net.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction:221]
- Profile Action SimpleSubjectCanonicalization: trimming whitespace of
input string 'theuserid' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.session.impl.DetectIdentitySwitch:168] - Profile
Action DetectIdentitySwitch: Identities from session and new authentication
result match, nothing to do - [node01uk2mhrhajtpqir5jq8wum6273] -
[99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.FinalizeAuthentication:116] - Profile
Action FinalizeAuthentication: Canonical principal name was established as
'theuserid' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG [net.shibboleth.idp.authn.impl.FinalizeAuthentication:229] - Profile
Action FinalizeAuthentication: Checking result for compatibility with
operator 'exact' and principal 'https://refeds.org/profile/mfa-level2' -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[net.shibboleth.idp.authn.principal.PrincipalEvalPredicateFactoryRegistry:126]
- Registry located predicate factory of type
'net.shibboleth.idp.authn.principal.impl.ExactPrincipalEvalPredicateFactory'
for principal type 'class
net.shibboleth.idp.saml.authn.principal.AuthnContextClassRefPrincipal' and
operator 'exact' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
WARN [net.shibboleth.idp.authn.impl.FinalizeAuthentication:164] - Profile
Action FinalizeAuthentication: Authentication result for flow authn/MFA did
not satisfy the request - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
WARN [org.opensaml.profile.action.impl.LogEvent:101] - A non-proceed event
occurred while processing the request: RequestUnsupported -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
DEBUG
[org.opensaml.saml.common.profile.logic.DefaultLocalErrorPredicate:172] -
Error event RequestUnsupported will be handled with response -
[node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]
----------------------------------------------------------------------------------------
Settings:
*authn.properties*
# Unset if you have advanced Duo integrations with individualized Principals
idp.authn.Duo.addDefaultPrincipals = false
idp.authn.Duo.supportedPrincipals = \
saml2/https://refeds.org/profile/mfa, \
saml2/https://refeds.org/profile/mfa-level2, \
saml1/https://refeds.org/profile/mfa, \
saml1/https://refeds.org/profile/mfa-level2
idp.authn.MFA.supportedPrincipals = \
saml2/urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport, \
saml2/urn:oasis:names:tc:SAML:2.0:ac:classes:Password, \
saml2/https://refeds.org/profile/mfa, \
saml2/https://refeds.org/profile/mfa-level2, \
saml1/urn:oasis:names:tc:SAML:1.0:am:password, \
saml1/https://refeds.org/profile/mfa, \
saml1/https://refeds.org/profile/mfa-level2
*duo-oidc.properties*
idp.authn.DuoOIDC.supportedPrincipals = \
saml2/https://refeds.org/profile/mfa, \
saml2/https://refeds.org/profile/mfa-level2, \
saml1/https://refeds.org/profile/mfa, \
saml1/https://refeds.org/profile/mfa-level2
idp.authn.DuoOIDC.addDefaultPrincipals = false
*duo-oidc-authn-config.xml*
<bean id="DefaultDuoOIDC"
parent="shibboleth.authn.DuoOIDC.DuoIntegration"
p:APIHost="%{idp.duo.oidc.apiHost:none}"
p:clientId="%{idp.duo.oidc.clientId:none}"
p:secretKey="%{idp.duo.oidc.secretKey:none}">
<property name="supportedPrincipals">
<list>
<bean parent="shibboleth.SAML2AuthnContextClassRef"
c:classRef="https://refeds.org/profile/mfa" />
<bean parent="shibboleth.SAML1AuthenticationMethod"
c:method="https://refeds.org/profile/mfa" />
</list>
</property>
</bean>
<bean id="Level2DuoOIDC"
parent="shibboleth.authn.DuoOIDC.DuoIntegration"
p:APIHost="%{idp.duo2.oidc.apiHost:none}"
p:clientId="%{idp.duo2.oidc.clientId:none}"
p:secretKey="%{idp.duo2.oidc.secretKey:none}">
<property name="supportedPrincipals">
<list>
<bean parent="shibboleth.SAML2AuthnContextClassRef"
c:classRef="https://refeds.org/profile/mfa-level2" />
<bean parent="shibboleth.SAML1AuthenticationMethod"
c:method="https://refeds.org/profile/mfa-level2" />
</list>
</property>
</bean>
<util:list id="DuoIntegrationList">
<ref bean="DefaultDuoOIDC" />
<ref bean="Level2DuoOIDC" />
</util:list>
<bean id="shibboleth.authn.DuoOIDC.DuoIntegrationStrategy"
parent="shibboleth.ContextFunctions.Scripted"
...same script as in the example...
On Thu, Sep 19, 2024 at 11:52 AM Cantor, Scott <cantor.2 at osu.edu> wrote:
> > I have learned that the order of the DuoIntegrationList is very
> > important. In the log, I can see the IDP is searching for my
> > SpecialDuo integration, but it's still getting lost when doing
> > SSO and sorting thru results.
>
> The order matters because the script that derives the one to use is built
> in a specific way to iterate over them looking for the first match, on the
> assumption that you want more strict rules to be used only when necessary.
> If there is no order that makes sense and they won't sort of subset each
> other, the whole approach probably isn't applicable.
>
> > Does anyone know of any other documentation specifically
> > for the DuoOIDC version of this functionality? Or a newer
> > description?
>
> I didn't do a V5 article but there's not any difference apart from it
> would be a Universal Prompt one to start with. It's largely s/Duo/DuoOIDC
> all over the place. The Duo plugin has general docs on the multiple
> integration support, I don't know that anything is missing.
>
> The REFEDS example is just a specific application of the feature that is
> usually similar to what people tend to do on campus.
>
> > Did anyone run into issues/pitfalls implementing this that
> > might help me? anything specific to DuoOIDC besides the
> > aforementioned bug?
>
> I don't think the bug even exists anymore, but I don't know exactly when
> it was fixed and it doesn't hurt anything.
>
> There's no way to really answer this, you have to use the logs to actually
> determine what specifically it's doing wrong, and you never actually said.
> There are all sorts of general issues related to the MFA flow being defined
> correctly, complications like user-specific policies getting in the way. It
> just depends what it's actually doing, but if it's picking an existing
> result when it shouldn't, that means the principal set just isn't right.
>
> Brown is a member, I would advise a support ticket so that logs can be
> included and a more detailed description of the problem provided.
>
> -- Scott
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240920/4344be80/attachment.htm>
More information about the users
mailing list