<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" id="owaParaStyle"></style>
</head>
<body fpstyle="1" ocsi="0">
<div style="direction: ltr;font-family: Tahoma;color: #000000;font-size: 10pt;">
<div>Hi,</div>
<div><br>
</div>
<div>I'm trying to hook my test SP to a test IdP that my identity management group controls.</div>
<div><br>
</div>
<div>I installed the metadata provider XML that they sent me, and I set my SSO element to point to them; but I'm getting the errors below.
<div>
<div><br>
</div>
<div><a href="https://nuxeo-dev.cdlib.org/nuxeo/" target="_blank">https://nuxeo-dev.cdlib.org/nuxeo/</a> is protected and worked with testshib.org -- going there now I get redirected around and end up here (without it ever prompting me to enter a username/password):</div>
<div>
<h1 style="font-family: Times; ">opensaml::FatalProfileException</h1>
<p style="font-family: Times; font-size: medium; ">The system encountered an error at Fri Jun 7 13:42:12 2013</p>
<p style="font-family: Times; font-size: medium; ">To report this problem, please contact the site administrator at <a href="mailto:root@localhost">root@localhost</a>.</p>
<p style="font-family: Times; font-size: medium; ">Please include the following message in any email:</p>
<p class="error" style="font-family: Times; font-size: medium; ">opensaml::FatalProfileException at (https://nuxeo-dev.cdlib.org/Shibboleth.sso/SAML2/POST)</p>
<p style="font-family: Times; font-size: medium; ">SAML response contained an error.</p>
<p style="font-family: Times; font-size: medium; ">Error from identity provider:</p>
<blockquote style="font-family: Times; font-size: medium; "><strong>Status:</strong> urn:oasis:names:tc:SAML:2.0:status:Responder<br>
<strong>Sub-Status:</strong> urn:oasis:names:tc:SAML:2.0:status:AuthnFailed</blockquote>
</div>
<div><br>
</div>
<div>
<pre class="line-pre" style="font-size: 12px; line-height: 16px; word-wrap: break-word; width: 4956px; margin-top: 0px; margin-bottom: 0px; padding: 0px; background-color: rgb(255, 255, 255); "><div class="line" id="file-authnfailed-txt-LC83" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">==> servers/shibboleth/var/log/httpd/native_warn.log <==</div><div class="line" id="file-authnfailed-txt-LC84" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 ERROR Shibboleth.Listener [22881] shib_handler: remoted message returned an error: SAML response contained an error.</div><div class="line" id="file-authnfailed-txt-LC85" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 ERROR Shibboleth.Apache [22881] shib_handler: SAML response contained an error.</div><div class="line" id="file-authnfailed-txt-LC86" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; "> </div><div class="line" id="file-authnfailed-txt-LC87" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">==> servers/shibboleth/var/log/shibboleth/shibd.log <==</div><div class="line" id="file-authnfailed-txt-LC88" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 DEBUG Shibboleth.Listener [2]: dispatching message (default/SAML2/POST)</div><div class="line" id="file-authnfailed-txt-LC89" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 DEBUG OpenSAML.MessageDecoder.SAML2POST [2]: validating input</div><div class="line" id="file-authnfailed-txt-LC90" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 DEBUG OpenSAML.MessageDecoder.SAML2POST [2]: decoded SAML message:</div><div class="line" id="file-authnfailed-txt-LC91" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; "><?xml version="1.0" encoding="UTF-8"?><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://nuxeo-dev.cdlib.org/Shibboleth.sso/SAML2/POST" ID="_5d32eef9dc33f2720aa5eb59937b8f5a" InResponseTo="_b8415074b602040366fb259249ffa6b9" IssueInstant="2013-06-07T21:13:21.010Z" Version="2.0"><saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://idt1.ucop.edu/idp/shibboleth</saml2:Issuer><saml2p:Status><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder"><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:AuthnFailed"/></saml2p:StatusCode></saml2p:Status></saml2p:Response></div><div class="line" id="file-authnfailed-txt-LC92" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 DEBUG OpenSAML.MessageDecoder.SAML2 [2]: extracting issuer from SAML 2.0 protocol message</div><div class="line" id="file-authnfailed-txt-LC93" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 DEBUG OpenSAML.MessageDecoder.SAML2 [2]: message from (https://idt1.ucop.edu/idp/shibboleth)</div><div class="line" id="file-authnfailed-txt-LC94" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 DEBUG OpenSAML.MessageDecoder.SAML2 [2]: searching metadata for message issuer...</div><div class="line" id="file-authnfailed-txt-LC95" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2]: evaluating message flow policy (replay checking on, expiration 60)</div><div class="line" id="file-authnfailed-txt-LC96" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 DEBUG XMLTooling.StorageService [2]: inserted record (_5d32eef9dc33f2720aa5eb59937b8f5a) in context (MessageFlow) with expiration (1370641461)</div><div class="line" id="file-authnfailed-txt-LC97" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 DEBUG XMLTooling.StorageService [2]: deleted record (4570afd04ef5eaa8fb7fcf69d044c04d) in context (RelayState)</div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">2013-06-07 14:13:22 DEBUG Shibboleth.SSO.SAML2 [2]: processing message against SAML 2.0 SSO profile</div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; "><br></div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">more logs here https://gist.github.com/tingletech/5732472 if they are helpful </div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; "><br></div><div class="line" id="file-authnfailed-txt-LC98"><font face="Consolas, Liberation Mono, Courier, monospace">I asked my IdP for </font><font face="Tahoma">his </font><span style="font-family: Verdana; font-size: 10px; line-height: normal; ">idp-process.log and he sent it to me. I find this error in his logs every time I tried to log in:</span><span style="font-family: Verdana; font-size: 10px; line-height: normal; "> </span></div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; "><br></div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">14:13:20.995 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserAuthServlet:77] - No remote user information was present in the request
14:13:20.995 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:144] - Returning control to authentication engine
14:13:20.995 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:209] - Processing incoming request
14:13:20.995 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:514] - Completing user authentication process
14:13:20.996 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:585] - Validating authentication was performed successfully
14:13:20.996 - ERROR [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:618] - No user identified by login handler.
14:13:20.997 - ERROR [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:563] - Authentication failed with the error:
edu.internet2.middleware.shibboleth.idp.authn.AuthenticationException: No user identified by login handler.
at edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine.validateSuccessfulAuthentication(AuthenticationEngine.java:619) [shibboleth-identityprovider-2.3.8.jar:na]
at edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine.completeAuthentication(AuthenticationEngine.java:537) [shibboleth-identityprovider-2.3.8.jar:na]
at edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine.service(AuthenticationEngine.java:225) [shibboleth-identityprovider-2.3.8.jar:na]
at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) [servlet-api.jar:na]
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290) [catalina.jar:6.0.29]
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) [catalina.jar:6.0.29]
at org.apache.catalina.core.ApplicationDispatcher.invoke(ApplicationDispatcher.java:646) [catalina.jar:6.0.29]
at org.apache.catalina.core.ApplicationDispatcher.processRequest(ApplicationDispatcher.java:436) [catalina.jar:6.0.29]
at org.apache.catalina.core.ApplicationDispatcher.doForward(ApplicationDispatcher.java:374) [catalina.jar:6.0.29]
at org.apache.catalina.core.ApplicationDispatcher.forward(ApplicationDispatcher.java:302) [catalina.jar:6.0.29]
at edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine.forwardRequest(AuthenticationEngine.java:196) [shibboleth-identityprovider-2.3.8.jar:na]
at edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine.returnToAuthenticationEngine(AuthenticationEngine.java:150) [shibboleth-identityprovider-2.3.8.jar:na]
</div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; "><br></div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">How can we make sure that remote user information is present in the request so that a user is identified by the login handler? Is this an issue on the SP end, or the IdP end?</div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; "><br></div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; ">Thanks -- Brian</div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; "><br></div><div class="line" id="file-authnfailed-txt-LC98" style="font-family: Consolas, 'Liberation Mono', Courier, monospace; "><br></div><div style="font-family: Consolas, 'Liberation Mono', Courier, monospace; "><br></div></pre>
</div>
</div>
</div>
</div>
</body>
</html>