Hello,<div>I'm troubleshooting an issue between shibboleth-sp and ADFS (2 ADFS servers behind the load balancer of <a href="http://login.foo.com">login.foo.com</a>) as the IdP where after replacing an apache front end SSL for a web site, the SSO is no longer working.</div>
<div><br></div><div>Users sign into the <a href="http://www.foo.com">www.foo.com</a>, which is all windows, but when they attempt to go to <a href="http://cms.foo.com">cms.foo.com</a> which is the apache/shibboleth piece, the following error message is thrown in shibd.log when I enable debugging:</div>
<div><br></div><div><div>2012-09-28 12:47:12 INFO Shibboleth.Listener [1]: detected socket closure, shutting down worker thread</div><div>2012-09-28 12:47:18 DEBUG Shibboleth.Listener [10]: dispatching message (default::getHeaders::Application)</div>
<div>2012-09-28 12:47:18 DEBUG Shibboleth.Listener [11]: dispatching message (default/Login::run::ADFSSI)</div><div>2012-09-28 12:47:18 INFO Shibboleth.SessionInitiator.ADFS [11]: unable to locate ADFS-aware identity provider role for provider (<a href="http://login.foo.com/adfs/services/trust">http://login.foo.com/adfs/services/trust</a>)</div>
<div>2012-09-28 12:47:18 DEBUG Shibboleth.Listener [11]: dispatching message (default/Login::run::SAML2SI)</div><div>2012-09-28 12:47:18 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [11]: validating input</div><div>2012-09-28 12:47:18 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [11]: marshalling, deflating, base64-encoding the message</div>
<div>2012-09-28 12:47:18 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [11]: marshalled message:</div><div><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="<a href="https://cms.foo.com/Shibboleth.sso/SAML2/POST">https://cms.foo.com/Shibboleth.sso/SAML2/POST</a>" Destination="<a href="https://login.foo.com/adfs/ls/">https://login.foo.com/adfs/ls/</a>" ID="_c3c745747ddb5ecda84dccfa78425caf" IssueInstant="2012-09-28T16:47:18Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://cms.foo.com/shibboleth">https://cms.foo.com/shibboleth</a></saml:Issuer><samlp:NameIDPolicy AllowCreate="1"/></samlp:AuthnRequest></div>
<div>2012-09-28 12:47:18 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [11]: message encoded, sending redirect to client</div><div>2012-09-28 12:47:18 DEBUG Shibboleth.Listener [12]: dispatching message (default/SAML2/POST)</div>
<div>2012-09-28 12:47:18 DEBUG OpenSAML.MessageDecoder.SAML2POST [12]: validating input</div><div>2012-09-28 12:47:18 DEBUG OpenSAML.MessageDecoder.SAML2POST [12]: decoded SAML message:</div><div>2012-09-28 12:47:18 DEBUG OpenSAML.MessageDecoder.SAML2 [12]: extracting issuer from SAML 2.0 protocol message</div>
<div>2012-09-28 12:47:18 DEBUG OpenSAML.MessageDecoder.SAML2 [12]: message from (<a href="http://login.foo.com/adfs/services/trust">http://login.foo.com/adfs/services/trust</a>)</div><div>2012-09-28 12:47:18 DEBUG OpenSAML.MessageDecoder.SAML2 [12]: searching metadata for message issuer...</div>
<div>2012-09-28 12:47:18 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [12]: evaluating message flow policy (replay checking on, expiration 60)</div><div>2012-09-28 12:47:18 DEBUG XMLTooling.StorageService [12]: inserted record (_36a781a5-70cf-451e-b238-de9fc8cb4b57) in context (MessageFlow) with expiration (1348851078)</div>
<div>2012-09-28 12:47:18 DEBUG Shibboleth.SSO.SAML2 [12]: processing message against SAML 2.0 SSO profile</div><div>2012-09-28 12:47:18 DEBUG XMLTooling.CredentialCriteria [12]: key algorithm didn't match ('AES' != 'RSA')</div>
<div>2012-09-28 12:47:18 DEBUG Shibboleth.SSO.SAML2 [12]: decrypted Assertion: <Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion" ID="_fc52a2da-c77e-4d44-bbb0-08501bcabad1" IssueInstant="2012-09-28T16:47:18.430Z" Version="2.0"><Issuer><a href="http://login.foo.com/adfs/services/trust">http://login.foo.com/adfs/services/trust</a></Issuer><ds:Signature xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"><ds:SignedInfo><ds:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/><ds:SignatureMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>"/><ds:Reference URI="#_fc52a2da-c77e-4d44-bbb0-08501bcabad1"><ds:Transforms><ds:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/><ds:Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/></ds:Transforms><ds:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>"/><ds:DigestValue>n2uxLhU7xqQx5PieceNiLDICukmJMZWVXAQbjFtJHhk=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>C/L0fq5hEuBPMs9hO/+vqZ17yYGDfyg+g6j2iEjdW7vWi22JfB+N/APZzHRZnZm8Lzv1KQb5NoG/wAiWJ2Yof5YTqlLPQ9a6zsWvBDjb17Uj6PSNYTvl/wVomjiwKjokM65IH0sZWZia0+2c6PU/2LGzANzZsb1PfxCFzbzMFOp25j7hNe4H/L7mWKgA8mFJS/OgPiorp4In++4Q0NB4H8Md3xZQwgvmbjC3o+SFVh3YJxzGpNt3q5bTmWGePJDffz7bSF15FytePBQ21OhjKV8S9DN871qVnLSSnq5qY9O8+gthMRVthpo10t4rQTvh58y+z9z88s711Zb1sMOCAQ==</ds:SignatureValue><KeyInfo xmlns="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"><ds:X509Data><ds:X509Certificate>Y2QoCpx+ngyA4ecM0PAWAI1pqJc0l6bas4e3VqVjZmHSvCQ6uICuzpPPlAlcb/AbGLEb3YeH7/3fPXKtCSKJ3W70wQUs8aalyiA2SVzz5Ht0Il9XnSHc/qC1r/wa8Vc0</ds:X509Certificate></ds:X509Data></KeyInfo></ds:Signature><Subject><NameID>4aHHPvWYKE+/ZTRUso2+eA==</NameID><SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><SubjectConfirmationData InResponseTo="_c3c745747ddb5ecda84dccfa78425caf" NotOnOrAfter="2012-09-28T16:52:18.430Z" Recipient="<a href="https://cms.foo.com/Shibboleth.sso/SAML2/POST">https://cms.foo.com/Shibboleth.sso/SAML2/POST</a>"/></SubjectConfirmation></Subject><Conditions NotBefore="2012-09-28T16:47:18.415Z" NotOnOrAfter="2012-09-28T17:47:18.415Z"><AudienceRestriction><Audience><a href="https://cms.foo.com/shibboleth">https://cms.foo.com/shibboleth</a></Audience></AudienceRestriction></Conditions><AttributeStatement><Attribute Name="<a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/title">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/title</a>"><AttributeValue><a href="mailto:ericalj@foo.com">ericalj@foo.com</a></AttributeValue></Attribute><Attribute Name="<a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn</a>"><AttributeValue><a href="mailto:ericalj@foo.com">ericalj@foo.com</a></AttributeValue></Attribute></AttributeStatement><AuthnStatement AuthnInstant="2012-09-28T16:15:43.349Z" SessionIndex="_fc52a2da-c77e-4d44-bbb0-08501bcabad1"><AuthnContext><AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</AuthnContextClassRef></AuthnContext></AuthnStatement></Assertion></div>
<div>2012-09-28 12:47:18 DEBUG Shibboleth.SSO.SAML2 [12]: extracting issuer from SAML 2.0 assertion</div><div>2012-09-28 12:47:18 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [12]: evaluating message flow policy (replay checking on, expiration 60)</div>
<div>2012-09-28 12:47:18 DEBUG XMLTooling.StorageService [12]: inserted record (_fc52a2da-c77e-4d44-bbb0-08501bcabad1) in context (MessageFlow) with expiration (1348851078)</div><div>2012-09-28 12:47:18 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [12]: validating signature profile</div>
<div>2012-09-28 12:47:18 DEBUG XMLTooling.CredentialCriteria [12]: keys didn't match</div><div>2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.ExplicitKey [12]: unable to validate signature, no credentials available from peer</div>
<div>2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: validating signature using certificate from within the signature</div><div>2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: signature verified with key inside signature, attempting certificate validation...</div>
<div>2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: checking that the certificate name is acceptable</div><div>2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: certificate subject: CN=<a href="http://login.foo.com">login.foo.com</a>,OU=OIT,O=US Dept of G,L=Washington,ST=DC,DC=va,DC=gov</div>
<div>2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: unable to match DN, trying TLS subjectAltName match</div><div>2012-09-28 12:47:18 DEBUG XMLTooling.TrustEngine.PKIX [12]: unable to match subjectAltName, trying TLS CN match</div>
<div>2012-09-28 12:47:18 ERROR XMLTooling.TrustEngine.PKIX [12]: certificate name was not acceptable</div><div>2012-09-28 12:47:18 ERROR OpenSAML.SecurityPolicyRule.XMLSigning [12]: unable to verify message signature with supplied trust engine</div>
<div>2012-09-28 12:47:18 WARN Shibboleth.SSO.SAML2 [12]: detected a problem with assertion: Message was signed, but signature could not be verified.</div></div><div><br></div><div>I'm unfortunately learning SSO as I go, so, I'm sorry if this seems like an obvious/simple issue. I am leaning towards an issue with the metadata, but I'm not certain how to check that further or resolve it if it is.</div>
<div><br></div><div>I've verified the sp-cert referenced in shibboleth2.xml is still valid and hasn't been touched. I've verified on the ADFS portion that the relying data matches the sp-cert as well.</div><div>
<br></div><div>Thanks,</div><div>Erica</div><div><br></div><div><br></div><div><br></div>