After Java upgrade idp-process.log Subject values are
Ward John
john.ward at univ-lyon2.fr
Tue Sep 15 16:48:29 UTC 2026
Thanks for the response Scott.
So what your saying is a printout of the principals in the idp-process.log is no longer possible / done, its deprecated as a feature I assume ? I have to go back to someone with this confirmation.
Cordialement,
John Ward
04 78 77 30 87
Bureau P.136
Pôle Réseau et Sécurité, Service Opérations
DSI, Université Lyon 2, Bron
-----Message d'origine-----
De : users <users-bounces at shibboleth.net> De la part de users-request at shibboleth.net
Envoyé : mardi 15 septembre 2026 14:00
À : users at shibboleth.net
Objet : users Digest, Vol 183, Issue 5
Send users mailing list submissions to
users at shibboleth.net
To subscribe or unsubscribe via the World Wide Web, visit
https://shibboleth.net/mailman/listinfo/users
or, via email, send a message with subject or body 'help' to
users-request at shibboleth.net
You can reach the person managing the list at
users-owner at shibboleth.net
When replying, please edit your Subject line so it is more specific than "Re: Contents of users digest..."
Today's Topics:
1. Re: After Java upgrade idp-process.log Subject values are
gone (Scott Cantor)
2. Duo Forceauthn authn failure starting 2029-09-08 (Brian Rose)
3. RE: Duo Forceauthn authn failure starting 2029-09-08
(Steven Teixeira)
----------------------------------------------------------------------
Message: 1
Date: Mon, 14 Sep 2026 08:34:00 -0400
From: Scott Cantor <scott at restingparrotsoftware.com>
To: Shib Users <users at shibboleth.net>
Subject: Re: After Java upgrade idp-process.log Subject values are
gone
Message-ID:
<4CB89F5A-9FF8-47FD-A523-0370BECDF08F at restingparrotsoftware.com>
Content-Type: text/plain; charset=us-ascii
> Has Java-11 become more strict in releasing the Subject ? Does anyone know how to fix this ?
The log line in question was logging the return value of javax.security.auth.Subject.getPrincipals()
Java's implementation of that method no longer returns an ordinary collection object that implements toString(), ergo nothing got logged, it was elided many years ago in response to that.
-- Scott
------------------------------
Message: 2
Date: Mon, 14 Sep 2026 08:31:13 -0700
From: Brian Rose <brose at pointnclick.com>
To: users at shibboleth.net
Subject: Duo Forceauthn authn failure starting 2029-09-08
Message-ID:
<CAKWPduiKNY8j-_rt3=_A1PLmfZ0+G25UinO2jJrrv7NnZNUsZA at mail.gmail.com>
Content-Type: text/plain; charset="utf-8"
We have several Shibboleth IDP customers with Duo MFA, and since mid-day last Tuesday 2029-09-08 two of them are reporting SSO failures when the end user has an existing Shibboleth SSO session, and a login to a new SP with forceauthn is sent.
We are seeing a authnfailure sent to the SP.
2026-09-08 14:18:24 (ET)
<saml2p:Status><saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Requester"><saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:AuthnFailed"/></saml2p:StatusCode><saml2p:StatusMessage>An
error occurred.</saml2p:StatusMessage></saml2p:Status>
Does anyone know if there were any default changes published just before then? I am still working with the two IDPs that are experiencing this issue to determine if anything was installed on their IDP systems which correlate to this, and I have opened a ticket with Duo as well.
--
Brian Rose
Point and Click Solutions, Inc.
Chief Information Security Officer
916-800-2338
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260914/26e37f65/attachment-0001.htm>
------------------------------
Message: 3
Date: Mon, 14 Sep 2026 15:59:36 +0000
From: Steven Teixeira <steixeira at csustan.edu>
To: Shib Users <users at shibboleth.net>
Subject: RE: Duo Forceauthn authn failure starting 2029-09-08
Message-ID:
<DM8PR17MB5077289033AE8ED4C3C5028AA1BB2 at DM8PR17MB5077.namprd17.prod.outlook.com>
Content-Type: text/plain; charset="utf-8"
Hi Brian,
I saw this topic recently, and the details are here: https://shibboleth.atlassian.net/browse/JDUO-102
I have not looked into this myself yet. I just thought I?d relay what I?d seen posted elsewhere in hopes it helps.
Steven Teixeira
From: users <users-bounces at shibboleth.net> On Behalf Of Brian Rose via users
Sent: Monday, September 14, 2026 8:31 AM
To: users at shibboleth.net
Cc: Brian Rose <brose at pointnclick.com>
Subject: Duo Forceauthn authn failure starting 2029-09-08
CAUTION: This message originated from outside of Stanislaus State. Do not click on links or open attachments unless you recognize the sender and are expecting the message.
We have several Shibboleth IDP customers with Duo MFA, and since mid-day last Tuesday 2029-09-08 two of them are reporting SSO failures when the end user has an existing Shibboleth SSO session, and a login to a new SP with forceauthn is sent.
We are seeing a authnfailure sent to the SP.
2026-09-08 14:18:24 (ET)
<saml2p:Status><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Requester"><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:AuthnFailed"/></saml2p:StatusCode><saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage></saml2p:Status>
Does anyone know if there were any default changes published just before then? I am still working with the two IDPs that are experiencing this issue to determine if anything was installed on their IDP systems which correlate to this, and I have opened a ticket with Duo as well.
--
Brian Rose
Point and Click Solutions, Inc.
Chief Information Security Officer
916-800-2338
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260914/194b740f/attachment-0001.htm>
------------------------------
Subject: Digest Footer
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
------------------------------
End of users Digest, Vol 183, Issue 5
*************************************
More information about the users
mailing list