<div dir="ltr">Hi,<div><br></div><div>I&#39;m setting up a Shibboleth Service Provider and have it now working pretty well in our staging environment.</div><div><br></div><div>Most times I can successfully complete the authentication round trip but occasionally I get the following exception on the initial request to the IdP (from the EDS and before authenticating with the IdP).</div>
<div><br></div><div><br></div><div><div>    opensaml::FatalProfileException</div><div><br></div><div>    The system encountered an error at Thu Jul 25 19:16:47 2013</div><div><br></div><div>    To report this problem, please contact the site administrator at <a href="mailto:support@example.org">support@example.org</a>.</div>
<div><br></div><div>    Please include the following message in any email:</div><div><br></div><div>    opensaml::FatalProfileException at (<a href="https://shibtest.teambox.com/Shibboleth.sso/SAML2/POST">https://shibtest.teambox.com/Shibboleth.sso/SAML2/POST</a>)</div>
<div><br></div><div>    SAML response contained an error.</div><div><br></div><div>    Error from identity provider:</div><div><br></div><div>        Status: urn:oasis:names:tc:SAML:2.0:status:Responder</div><div>        Sub-Status: urn:oasis:names:tc:SAML:2.0:status:AuthnFailed</div>
</div><div><br></div><div><br></div><div>After clearing cookies and retrying it works fine.</div><div><br></div><div>I was hoping someone could provide some pointers as to how I can go about debugging this issue.</div><div>
<br></div><div style>Any advice will be much appreciated.</div><div style><br></div><div style>Regards,</div><div style><br></div><div style>Saimon Moore</div></div>