<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Harlow Solid Italic";
        panose-1:4 3 6 4 2 15 2 2 13 2;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal>Hello everyone,<o:p></o:p></p><p class=MsoNormal>I am new to the group and to Shibboleth as well.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>At Kutztown University, we are working on integrating Office365 into our brand new Shibboleth environment. The Office365 domain is set up for SSO. After typing in the username, the login page redirects to a Shibboleth page displaying the following error.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>ERROR<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>An error occurred while processing your request. Please contact your helpdesk or user ID office for assistance.<o:p></o:p></p><p class=MsoNormal>This service requires cookies. Please ensure that they are enabled and try your going back to your desired resource and trying to login again.<o:p></o:p></p><p class=MsoNormal>Use of your browser's back button may cause specific errors that can be resolved by going back to your desired resource and trying to login again.<o:p></o:p></p><p class=MsoNormal>If you think you were sent here in error, please contact technical support<o:p></o:p></p><p class=MsoNormal><b>Error Message: Error decoding authentication request message<o:p></o:p></b></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>From what I can tell, the HTTP POST method is unable to decode the message. Any thoughts? <o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>The idp-process.log shows the following<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - DEBUG [edu.internet2.middleware.shibboleth.idp.session.IdPSessionFilter:160] - No session associated with session ID NmMyY2NhZjQ3Mzk0YzgzZjM0ZTAxN2IwNmE0M2YwZGYyNzRiNWE5YjdlMGI3N2IxYjUxNDJkNjVmM2JmZmE0MQ== - session must have timed out<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - INFO [Shibboleth-Access:74] - 20130417T154729Z|156.12.2.28|idp.kutztown.edu:443|/profile/SAML2/POST/SSO|<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:86] - shibboleth.HandlerManager: Looking up profile handler for request path: /SAML2/POST/SSO<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:97] - shibboleth.HandlerManager: Located profile handler of the following type for the request path: edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:325] - LoginContext key cookie was not present in request<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:186] - Incoming request does not contain a login context, processing as first leg of request<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:337] - Decoding message with decoder binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST'<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - DEBUG [org.opensaml.ws.message.decoder.BaseMessageDecoder:76] - Beginning to decode message from inbound transport of type: org.opensaml.ws.transport.http.HttpServletRequestAdapter<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:371] - Error decoding authentication request message<o:p></o:p></p><p class=MsoNormal>org.opensaml.ws.message.decoder.MessageDecodingException: <b>This message deocoder only supports the HTTP POST method<o:p></o:p></b></p><p class=MsoNormal> at org.opensaml.saml2.binding.decoding.HTTPPostDecoder.doDecode(HTTPPostDecoder.java:83) ~[opensaml-2.5.3.jar:na]<o:p></o:p></p><p class=MsoNormal> at org.opensaml.ws.message.decoder.BaseMessageDecoder.decode(BaseMessageDecoder.java:79) ~[openws-1.4.4.jar:na]<o:p></o:p></p><p class=MsoNormal> at org.opensaml.saml2.binding.decoding.BaseSAML2MessageDecoder.decode(BaseSAML2MessageDecoder.java:70) ~[opensaml-2.5.3.jar:na]<o:p></o:p></p><p class=MsoNormal> at edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler.decodeRequest(SSOProfileHandler.java:357) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></p><p class=MsoNormal> at edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler.performAuthentication(SSOProfileHandler.java:209) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></p><p class=MsoNormal> at edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler.processRequest(SSOProfileHandler.java:187) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></p><p class=MsoNormal> at edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler.processRequest(SSOProfileHandler.java:88) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></p><p class=MsoNormal> at edu.internet2.middleware.shibboleth.common.profile.ProfileRequestDispatcherServlet.service(ProfileRequestDispatcherServlet.java:84) [shibboleth-common-1.3.7.jar:na]<o:p></o:p></p><p class=MsoNormal> at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) [servlet-api.jar:na]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at edu.internet2.middleware.shibboleth.idp.util.NoCacheFilter.doFilter(NoCacheFilter.java:50) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at edu.internet2.middleware.shibboleth.idp.session.IdPSessionFilter.doFilter(IdPSessionFilter.java:81) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at edu.internet2.middleware.shibboleth.common.log.SLF4JMDCCleanupFilter.doFilter(SLF4JMDCCleanupFilter.java:52) [shibboleth-common-1.3.7.jar:na]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:233) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:191) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:470) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:103) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:293) [catalina.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:861) [tomcat-coyote.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:606) [tomcat-coyote.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:489) [tomcat-coyote.jar:6.0.36]<o:p></o:p></p><p class=MsoNormal> at java.lang.Thread.run(Unknown Source) [na:1.7.0_11]<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:325] - LoginContext key cookie was not present in request<o:p></o:p></p><p class=MsoNormal>11:47:29.090 - DEBUG [edu.internet2.middleware.shibboleth.idp.ui.ServiceContactTag:177] - No relying party, nothing to display<o:p></o:p></p><p class=MsoNormal>11:47:29.184 - DEBUG [edu.internet2.middleware.shibboleth.idp.session.IdPSessionFilter:160] - No session associated with session ID NmMyY2NhZjQ3Mzk0YzgzZjM0ZTAxN2IwNmE0M2YwZGYyNzRiNWE5YjdlMGI3N2IxYjUxNDJkNjVmM2JmZmE0MQ== - session must have timed out<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Thanks!<o:p></o:p></p><p class=MsoNormal>Dave<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><span style='font-size:16.0pt;font-family:"Harlow Solid Italic"'>David A. Jones<o:p></o:p></span></p><p class=MsoNormal>Enterprise Systems Analyst<o:p></o:p></p><p class=MsoNormal>KU Servers & Security<o:p></o:p></p></div></body></html>