detected a problem with assertion: Unable to establish security of incoming assertion.

George Maynard George.Maynard at ltimindtree.com
Thu Sep 26 16:42:27 UTC 2024


Hello,
When I login to the application URL I am successfully redirected to the IDP portal and able to login with out issue, however once I have logged in and it sends me back to the application I get the above error

I am relatively new to Shibboleth, can I know where to start checking?

Here are some sample from the log

2024-09-26 10:50:12 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: extracting issuer from SAML 2.0 protocol message
2024-09-26 10:50:12 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: message from (sso-portal-sit.fst.lntinfotech.com)
2024-09-26 10:50:12 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: searching metadata for message issuer...
2024-09-26 10:50:12 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: recovered request/response correlation value (_f977128e1bfe7ae6435e3aaafa2ebe0e)
2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: evaluating message flow policy (correlation off, replay checking on, expiration 60)
2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: ignoring InResponseTo, correlation checking is disabled
2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: evaluating message flow policy (correlation off, replay checking on, expiration 60)
2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: ignoring InResponseTo, correlation checking is disabled
2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [2] [default]: ignoring InResponseTo, correlation checking is disabled
2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [2] [default]: assertion satisfied bearer confirmation requirements
2024-09-26 10:50:12 WARN Shibboleth.SSO.SAML2 [2] [default]: detected a problem with assertion: Unable to establish security of incoming assertion.
2024-09-26 10:50:12 WARN Shibboleth.SSO.SAML2 [2] [default]: error processing incoming assertion: Unable to establish security of incoming assertion.
2024-09-26 10:50:12 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1] [default]: validating input
2024-09-26 10:50:12 DEBUG OpenSAML.MessageEncoder.SAML2 [1] [default]: tracking request (_253d5c2b70eab4c93dfe0e0bcf7a299d) against RelayState token (ss:mem:50d61be8b239b85b525dd1fb65ee4e6f9331b671f639d6989e0a03b05e56663c)
2024-09-26 10:50:12 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1] [default]: marshalling, deflating, base64-encoding the message
2024-09-26 10:50:12 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1] [default]: marshalled message:


________________________________

The contents of this e-mail and any attachment(s) may contain confidential or privileged information for the intended recipient(s). Unintended recipients are prohibited from taking action on the basis of information in this e-mail and using or disseminating the information, and must notify the sender and delete it from their system. LTIMindtree will not accept responsibility or liability for the accuracy or completeness of, or the presence of any virus or disabling code in this e-mail.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240926/1d8f3727/attachment.htm>


More information about the users mailing list