Anyone can help me?<br><br>Thanks<br><br><div class="gmail_quote">2011/11/28 Daniele Russo <span dir="ltr"><<a href="mailto:ruda76@gmail.com">ruda76@gmail.com</a>></span><br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
Hi, below the most important rows of the debug log of idp.<div><div class="h5"><br>I hope someone can help me.<br><br>10:40:57.898 - INFO [Shibboleth-Access:74] - 20111128T094057Z|93.70.49.139|www.inarcassa.it:443|/profile/SAML2/Redirect/SSO|<br>
10:40:57.899 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:86] - shibboleth.HandlerManager: Looking up profile handler for request path: /SAML2/Redirect/SSO<br>10:40:57.899 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:97] - shibboleth.HandlerManager: Located profile handler of the following type for the request path: edu.internet2.middleware.shibboleth.idp.<br>
profile.saml2.SSOProfileHandler<br>10:40:57.899 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:323] - LoginContext key cookie was not present in request<br>10:40:57.899 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:160] - Incoming request does not contain a login context, processing as first leg of request<br>
10:40:57.899 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:312] - Decoding message with decoder binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect'<br>10:40:57.901 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128] - Looking up relying party configuration for <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a><br>
10:40:57.901 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134] - No custom relying party configuration found for <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a>, looking up configu<br>
ration based on metadata groups.<br>10:40:57.901 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157] - No custom or group-based relying party configuration found for <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a>. Usi<br>
ng default relying party configuration.<br>10:40:57.901 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:333] - Decoded request from relying party '<a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a>'<br>
10:40:57.902 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128] - Looking up relying party configuration for <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a><br>
10:40:57.902 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134] - No custom relying party configuration found for <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a>, looking up configu<br>
ration based on metadata groups.<br>10:40:57.902 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157] - No custom or group-based relying party configuration found for <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a>. Usi<br>
ng default relying party configuration.<br>10:40:57.902 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:203] - Creating login context and transferring control to authentication engine<br>
10:40:57.903 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:169] - Storing LoginContext to StorageService partition loginContexts, key 35552361-5d87-444b-b305-0ca58d7e64fe<br>
10:40:57.903 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:216] - Redirecting user to authentication engine at <a href="https://www.inarcassa.it:443/idp/AuthnEngine" target="_blank">https://www.inarcassa.it:443/idp/AuthnEngine</a><br>
10:40:57.983 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:209] - Processing incoming request<br>10:40:57.983 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:240] - Beginning user authentication process.<br>
10:40:57.983 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:286] - Filtering configured LoginHandlers: {urn:oasis:names:tc:SAML:2.0:ac:classes:PreviousSession=<a href="http://edu.internet2.middleware.shibboleth.idp.authn.pr" target="_blank">edu.internet2.middleware.shibboleth.idp.authn.pr</a><br>
ovider.PreviousSessionLoginHandler@1e73498, urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport=edu.internet2.middleware.shibboleth.idp.authn.provider.UsernamePasswordLoginHandler@2e1b6c}<br>10:40:57.983 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:335] - Filtering out previous session login handler because there is no existing IdP session<br>
10:40:57.983 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:388] - Forced authentication is required, filtering possible login handlers accordingly<br>10:40:57.984 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:409] - Authentication handlers remaining after forced authentication requirement filtering: {urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtect<br>
edTransport=edu.internet2.middleware.shibboleth.idp.authn.provider.UsernamePasswordLoginHandler@2e1b6c}<br>10:40:57.984 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:467] - Selecting appropriate login handler from filtered set {urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport=edu.internet2.middl<br>
eware.shibboleth.idp.authn.provider.UsernamePasswordLoginHandler@2e1b6c}<br>10:40:57.984 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:500] - Authenticating user with login handler of type edu.internet2.middleware.shibboleth.idp.authn.provider.UsernamePasswordLoginHandler<br>
10:40:57.984 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:169] - Storing LoginContext to StorageService partition loginContexts, key 0f036b58-d567-4517-b7ea-b6d28ca6f7a5<br>10:40:57.984 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.provider.UsernamePasswordLoginHandler:66] - Redirecting to <a href="https://www.inarcassa.it:443/idp/Authn/UserPassword" target="_blank">https://www.inarcassa.it:443/idp/Authn/UserPassword</a><br>
10:40:58.063 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.provider.UsernamePasswordLoginServlet:150] - Redirecting to login page /login.jsp<br></div></div>....<div class="im"><br>10:41:00.117 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:778] - Encoding response to SAML request _0cf7fef8f3c9c338a5da4459da3e9a85 from relying party <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a><br>
10:41:00.120 - INFO [Shibboleth-Audit:970] - 20111128T094100Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_0cf7fef8f3c9c338a5da4459da3e9a85|<a href="https://www.inarcassa.it/shibboleth%7Curn:mace:shibboleth:2.0:profiles:saml2:sso%7Chttps://ww" target="_blank">https://www.inarcassa.it/shibboleth|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://ww</a><br>
<a href="http://w.inarcassa.it/idp/shibboleth%7Curn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST%7C_28c086360316f84ec2ff95d645460ed0%7CYYYYYYYYYY%7Curn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport%7CProfilo,CodiceEnte,Contatti,CodiceFiscale,Ruol" target="_blank">w.inarcassa.it/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_28c086360316f84ec2ff95d645460ed0|YYYYYYYYYY|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|Profilo,CodiceEnte,Contatti,CodiceFiscale,Ruol</a><br>
o,CodiceUtente,Matricola,|||<br>10:41:03.302 - DEBUG [edu.internet2.middleware.shibboleth.idp.session.IdPSessionFilter:160] - No session associated with session ID ZGZlN2JmZTVlNmM2MDA4NDc1Zjk5Mjg2MmRiZWM0NGM2ODVkYmYzMjFjNDk2Y2RhOGM4MzVhZjEwYTE1YjMyMg== - session must<br>
have timed out<br></div>....<div class="im"><br>10:41:20.328 - INFO [Shibboleth-Access:74] - 20111128T094120Z|93.70.49.139|www.inarcassa.it:443|/profile/SAML2/Redirect/SSO|<br>10:41:20.328 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:86] - shibboleth.HandlerManager: Looking up profile handler for request path: /SAML2/Redirect/SSO<br>
10:41:20.329 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:97] - shibboleth.HandlerManager: Located profile handler of the following type for the request path: edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler<br>
10:41:20.329 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:163] - Incoming request contains a login context, processing as second leg of request<br>10:41:20.329 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:572] - Unbinding LoginContext<br>
10:41:20.329 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:598] - Expiring LoginContext cookie<br>10:41:20.329 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:607] - Removing LoginContext, with key 0f036b58-d567-4517-b7ea-b6d28ca6f7a5, from StorageService partition loginContexts<br>
10:41:20.330 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128] - Looking up relying party configuration for <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a><br>
10:41:20.330 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134] - No custom relying party configuration found for <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a>, looking up configuration based on metadata groups.<br>
10:41:20.330 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157] - No custom or group-based relying party configuration found for <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a>. Using default relying party configuration.<br>
10:41:20.331 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:472] - Resolving attributes for principal 'null' for SAML request from relying party '<a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a>'<br>
</div>
....<div class="im HOEnZb"><br>10:41:20.429 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:778] - Encoding response to SAML request _37239fdb6e3f76b3008ee0249f7c3518 from relying party <a href="https://www.inarcassa.it/shibboleth" target="_blank">https://www.inarcassa.it/shibboleth</a><br>
10:41:20.431 - INFO [Shibboleth-Audit:970] - 20111128T094120Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_37239fdb6e3f76b3008ee0249f7c3518|<a href="https://www.inarcassa.it/shibboleth%7Curn:mace:shibboleth:2.0:profiles:saml2:sso%7Chttps://www.inarcassa.it/idp/shibboleth%7Curn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST%7C_4cee0f36347dd1617d516a89775a489f%7C%7C%7C%7C%7C%7C" target="_blank">https://www.inarcassa.it/shibboleth|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://www.inarcassa.it/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_4cee0f36347dd1617d516a89775a489f||||||</a><br>
<br><br><br></div><div class="HOEnZb"><div class="h5"><div class="gmail_quote">2011/11/22 Paul Hethmon <span dir="ltr"><<a href="mailto:paul.hethmon@clareitysecurity.com" target="_blank">paul.hethmon@clareitysecurity.com</a>></span><br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div style="word-wrap:break-word;color:rgb(0,0,0);font-size:14px;font-family:Calibri,sans-serif">
<div>
<div>
<div>You need to set your IdP logging level to debug and follow what happens in the logs for these cases.</div>
<div><br>
</div>
<div>
<div>
<div>-- </div>
<div><br>
</div>
</div>
<div>
<div>Paul Hethmon</div>
<div>Chief Software Architect</div>
<div>Clareity Security, LLC</div>
<div>o) <a href="tel:865.824.1350" value="+18658241350" target="_blank">865.824.1350</a></div>
<div>c) <a href="tel:865.250.3517" value="+18652503517" target="_blank">865.250.3517</a></div>
<div>e) <a href="mailto:paul.hethmon@clareitysecurity.com" target="_blank">paul.hethmon@clareitysecurity.com</a></div>
</div>
<div><br>
</div>
</div>
</div>
</div>
<div><br>
</div>
<span>
<div style="font-family:Calibri;font-size:11pt;text-align:left;color:black;BORDER-BOTTOM:medium none;BORDER-LEFT:medium none;PADDING-BOTTOM:0in;PADDING-LEFT:0in;PADDING-RIGHT:0in;BORDER-TOP:#b5c4df 1pt solid;BORDER-RIGHT:medium none;PADDING-TOP:3pt">
<span style="font-weight:bold">From: </span>Daniele Russo <<a href="mailto:ruda76@gmail.com" target="_blank">ruda76@gmail.com</a>><br>
<span style="font-weight:bold">Reply-To: </span>Shibboleth Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<span style="font-weight:bold">Date: </span>Tue, 22 Nov 2011 17:56:28 +0100<br>
<span style="font-weight:bold">To: </span>Shibboleth Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<span style="font-weight:bold">Subject: </span>Re: null principal in attribute resolver<br>
</div><div><div>
<div><br>
</div>
Anyone have this same problem?<br>
No solutions?<br>
<br>
<div class="gmail_quote">2011/11/21 Daniele Russo <span dir="ltr"><<a href="mailto:ruda76@gmail.com" target="_blank">ruda76@gmail.com</a>></span><br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Hi all, I have a strange problem with shibboleth IDP 2.3.5.<br>
IDP is configured with UsernamePassword login handler, I use tigish library to authenticate users on the DB.<br>
All works, but occasionally IDP doesn't return attributes to SP and this strange problem only occurs in production enviroment.<br>
In debugging I noticed that the principal is enhanced in the authentication phase, while in the attribute resolver phase is null.<br>
This problem occurs with various operating systems and browsers.<br>
<br>
<span lang="en"><span></span></span>Mozilla/5.0 (Windows; U; Windows NT 6.0; it; rv:1.9.2.23) Gecko/20110920 Firefox/3.6.23<br>
Mozilla/5.0 (Windows NT 5.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1<br>
<br>
Thanks<span><font color="#888888"><br>
<br>
Daniele<br>
<br>
</font></span></blockquote>
</div>
<br></div></div>
-- To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a></span>
</div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br>
</div></div></blockquote></div><br>