<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Verdana;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
        {font-family:Times;
        panose-1:2 2 6 3 5 4 5 2 3 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
h1
        {mso-style-priority:9;
        mso-style-link:"Heading 1 Char";
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:24.0pt;
        font-family:"Times New Roman","serif";
        font-weight:bold;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
span.Heading1Char
        {mso-style-name:"Heading 1 Char";
        mso-style-priority:9;
        mso-style-link:"Heading 1";
        font-family:"Cambria","serif";
        color:#365F91;
        font-weight:bold;}
p.error, li.error, div.error
        {mso-style-name:error;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;}
span.EmailStyle23
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.sc3
        {mso-style-name:sc3;}
span.re0
        {mso-style-name:re0;}
span.st0
        {mso-style-name:st0;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Looking at this from afar (meaning, I don’t have access to either server myself), I see two possible issues in the AuthnRequest you are sending:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">A missing NameIDPolicy Format and a missing “RequestedAuthnContext” section.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">If I change the SAML you’re generating from this:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> AssertionConsumerServiceURL="https://nuxeo-dev.cdlib.org/Shibboleth.sso/SAML2/POST"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> Destination="https://idt1.ucop.edu/idp/profile/SAML2/Redirect/SSO"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> ID="_6d74840da8429abbcc655b947b9af644"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> IssueInstant="2013-06-07T22:11:58Z"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> Version="2.0"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> ><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://nuxeo.cdlib.org/sp</saml:Issuer><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> <samlp:NameIDPolicy AllowCreate="1" /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"></samlp:AuthnRequest><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">To include both the NameID Format and the RequestedAuthnContext elements (elements added in boldface, below):<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> AssertionConsumerServiceURL="https://nuxeo-dev.cdlib.org/Shibboleth.sso/SAML2/POST"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> Destination="https://idt1.ucop.edu/idp/profile/SAML2/Redirect/SSO"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> ID="_6d74840da8429abbcc655b947b9af644"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> IssueInstant="2013-06-07T22:11:58Z"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> Version="2.0"<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> ><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://nuxeo.cdlib.org/sp</saml:Issuer><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> <samlp:NameIDPolicy AllowCreate="1"
<b>Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"</b> /><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">
<b> <samlp:RequestedAuthnContext Comparison="exact"><o:p></o:p></b></span></p>
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> <saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef><o:p></o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> </samlp:RequestedAuthnContext><o:p></o:p></span></b></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"></samlp:AuthnRequest><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Then I am prompted for login as expected, and (since I have an account on said IdP) I get back to
<a href="https://nuxeo-dev/cdlib.org">https://nuxeo-dev/cdlib.org</a> with the generic “It works!” message. (I did this at 4:05PM, if you want to see if the logs reflect my connection and/or indicate any other parsing errors).<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">I’ll have to defer to people on this list as to whether the original request is malformed, or whether the IdP is failing to handle a valid configuration, but
if you can change the format of your request, it looks like you will at least get the login prompt and a return back to your application.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">--- Eric<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Brian Tingle<br>
<b>Sent:</b> Friday, June 07, 2013 3:00 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> AuthnFailed and SP IdP test configuration<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black">Hi,<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black">I'm trying to hook my test SP to a test IdP that my identity management group controls.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black">I installed the metadata provider XML that they sent me, and I set my SSO element to point to them; but I'm getting the errors below.
<o:p></o:p></span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black"><a href="https://nuxeo-dev.cdlib.org/nuxeo/" target="_blank">https://nuxeo-dev.cdlib.org/nuxeo/</a> is protected and worked with testshib.org -- going there now
I get redirected around and end up here (without it ever prompting me to enter a username/password):<o:p></o:p></span></p>
</div>
<div>
<h1><span style="font-family:"Times","serif";color:black">opensaml::FatalProfileException<o:p></o:p></span></h1>
<p><span style="font-size:13.5pt;font-family:"Times","serif";color:black">The system encountered an error at Fri Jun 7 13:42:12 2013<o:p></o:p></span></p>
<p><span style="font-size:13.5pt;font-family:"Times","serif";color:black">To report this problem, please contact the site administrator at <a href="mailto:root@localhost">root@localhost</a>.<o:p></o:p></span></p>
<p><span style="font-size:13.5pt;font-family:"Times","serif";color:black">Please include the following message in any email:<o:p></o:p></span></p>
<p class="error"><span style="font-size:13.5pt;font-family:"Times","serif";color:black">opensaml::FatalProfileException at (<a href="https://nuxeo-dev.cdlib.org/Shibboleth.sso/SAML2/POST">https://nuxeo-dev.cdlib.org/Shibboleth.sso/SAML2/POST</a>)<o:p></o:p></span></p>
<p><span style="font-size:13.5pt;font-family:"Times","serif";color:black">SAML response contained an error.<o:p></o:p></span></p>
<p><span style="font-size:13.5pt;font-family:"Times","serif";color:black">Error from identity provider:<o:p></o:p></span></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><strong><span style="font-size:13.5pt;font-family:"Times","serif";color:black">Status:</span></strong><span style="font-size:13.5pt;font-family:"Times","serif";color:black"> urn:oasis:names:tc:SAML:2.0:status:Responder<br>
<strong><span style="font-family:"Times","serif"">Sub-Status:</span></strong> urn:oasis:names:tc:SAML:2.0:status:AuthnFailed<o:p></o:p></span></p>
</blockquote>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black"><o:p> </o:p></span></p>
</div>
<div>
<div id="file-authnfailed-txt-LC83">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">==> servers/shibboleth/var/log/httpd/native_warn.log <==<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC84">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 ERROR Shibboleth.Listener [22881] shib_handler: remoted message returned an error: SAML response contained an error.<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC85">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 ERROR Shibboleth.Apache [22881] shib_handler: SAML response contained an error.<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC86">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> <o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC87">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">==> servers/shibboleth/var/log/shibboleth/shibd.log <==<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC88">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 DEBUG Shibboleth.Listener [2]: dispatching message (default/SAML2/POST)<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC89">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 DEBUG OpenSAML.MessageDecoder.SAML2POST [2]: validating input<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC90">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 DEBUG OpenSAML.MessageDecoder.SAML2POST [2]: decoded SAML message:<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC91">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"><?xml version="1.0" encoding="UTF-8"?><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="<a href="https://nuxeo-dev.cdlib.org/Shibboleth.sso/SAML2/POST">https://nuxeo-dev.cdlib.org/Shibboleth.sso/SAML2/POST</a>" ID="_5d32eef9dc33f2720aa5eb59937b8f5a" InResponseTo="_b8415074b602040366fb259249ffa6b9" IssueInstant="2013-06-07T21:13:21.010Z" Version="2.0"><saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"><a href="https://idt1.ucop.edu/idp/shibboleth%3c/saml2:Issuer%3e%3csaml2p:Status%3e%3csaml2p:StatusCode">https://idt1.ucop.edu/idp/shibboleth</saml2:Issuer><saml2p:Status><saml2p:StatusCode</a> Value="urn:oasis:names:tc:SAML:2.0:status:Responder"><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:AuthnFailed"/></saml2p:StatusCode></saml2p:Status></saml2p:Response><o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC92">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 DEBUG OpenSAML.MessageDecoder.SAML2 [2]: extracting issuer from SAML 2.0 protocol message<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC93">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 DEBUG OpenSAML.MessageDecoder.SAML2 [2]: message from (<a href="https://idt1.ucop.edu/idp/shibboleth">https://idt1.ucop.edu/idp/shibboleth</a>)<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC94">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 DEBUG OpenSAML.MessageDecoder.SAML2 [2]: searching metadata for message issuer...<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC95">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2]: evaluating message flow policy (replay checking on, expiration 60)<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC96">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 DEBUG XMLTooling.StorageService [2]: inserted record (_5d32eef9dc33f2720aa5eb59937b8f5a) in context (MessageFlow) with expiration (1370641461)<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC97">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 DEBUG XMLTooling.StorageService [2]: deleted record (4570afd04ef5eaa8fb7fcf69d044c04d) in context (RelayState)<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">2013-06-07 14:13:22 DEBUG Shibboleth.SSO.SAML2 [2]: processing message against SAML 2.0 SSO profile<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"><o:p> </o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">more logs here <a href="https://gist.github.com/tingletech/5732472">https://gist.github.com/tingletech/5732472</a> if they are helpful <o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"><o:p> </o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">I asked my IdP for </span><span style="font-size:9.0pt;font-family:"Tahoma","sans-serif";color:black">his </span><span style="font-size:7.5pt;font-family:"Verdana","sans-serif";color:black">idp-process.log and he sent it to me. I find this error in his logs every time I tried to log in: </span><span style="font-size:9.0pt;color:black"><o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"><o:p> </o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">14:13:20.995 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserAuthServlet:77] - No remote user information was present in the request<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">14:13:20.995 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:144] - Returning control to authentication engine<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">14:13:20.995 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:209] - Processing incoming request<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">14:13:20.995 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:514] - Completing user authentication process<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">14:13:20.996 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:585] - Validating authentication was performed successfully<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">14:13:20.996 - ERROR [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:618] - No user identified by login handler.<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">14:13:20.997 - ERROR [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:563] - Authentication failed with the error:<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">edu.internet2.middleware.shibboleth.idp.authn.AuthenticationException: No user identified by login handler.<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine.validateSuccessfulAuthentication(AuthenticationEngine.java:619) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine.completeAuthentication(AuthenticationEngine.java:537) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine.service(AuthenticationEngine.java:225) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) [servlet-api.jar:na]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290) [catalina.jar:6.0.29]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) [catalina.jar:6.0.29]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at org.apache.catalina.core.ApplicationDispatcher.invoke(ApplicationDispatcher.java:646) [catalina.jar:6.0.29]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at org.apache.catalina.core.ApplicationDispatcher.processRequest(ApplicationDispatcher.java:436) [catalina.jar:6.0.29]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at org.apache.catalina.core.ApplicationDispatcher.doForward(ApplicationDispatcher.java:374) [catalina.jar:6.0.29]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at org.apache.catalina.core.ApplicationDispatcher.forward(ApplicationDispatcher.java:302) [catalina.jar:6.0.29]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine.forwardRequest(AuthenticationEngine.java:196) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></span></pre>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"> at edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine.returnToAuthenticationEngine(AuthenticationEngine.java:150) [shibboleth-identityprovider-2.3.8.jar:na]<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"><o:p> </o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">How can we make sure that remote user information is present in the request so that a user is identified by the login handler? Is this an issue on the SP end, or the IdP end?<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"><o:p> </o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black">Thanks -- Brian<o:p></o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"><o:p> </o:p></span></pre>
</div>
<div id="file-authnfailed-txt-LC98">
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"><o:p> </o:p></span></pre>
</div>
<div>
<pre style="line-height:12.0pt;background:white"><span style="font-size:9.0pt;font-family:Consolas;color:black"><o:p> </o:p></span></pre>
</div>
</div>
</div>
</div>
</div>
</div>
</body>
</html>