<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
I turned on debug logging for IDP. I see a certificate sent in the exchange. It seems to be the right one. I see this cert in the SAML response from my IDP (idpt):
<div><br>
</div>
<div>
<div> <ds:SignatureValue>ZKwMuET4qDGL2CdwIuOjJOpz1QuMNWZvcew+AnsgBJB6znL19zdCAVBBuScMhqJ8OQJynZBmskp5xhxS9Gnr0GEfr9eLcHh+GBP3eSrjoaMwhPznUSrBe84KIwSZNPexVgf7egCS/c05c+v7RK2xrcDs33I6qcVTxPF+6i0ViM5cLP7RMRkvqKOJ82jSEk8zPxUQhlzd7AwJY4YIBFe84fYidfNxWxqdop8iOglUScJ2R0Tl1NtzsZUCL7oVf65tU9sPoD3TmSbbbvvNw84AxPIE5tgrANGxCAs8uSyI1KnesdTlorta3Z+DzlkFlg8TaIwwkZL2zvoXC+0dGrrG5Q==</ds:SignatureValue></div>
<div> <ds:KeyInfo></div>
<div> <ds:X509Data></div>
<div> <ds:X509Certificate>MIIDVDCCAjygAwIBAgIVAJ8yKHKyn+jtv2SGeaU0ssFAVLaYMA0GCSqGSIb3DQEBBQUAMCUxIzAh</div>
<div>BgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEzMTExNDA1MzIwNloXDTMzMTEx</div>
<div>NDA1MzIwNlowJTEjMCEGA1UEAxMaaWRwdC5xYXRhci1tZWQuY29ybmVsbC5lZHUwggEiMA0GCSqG</div>
<div>SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+Oo5QLdGh0Y4OrLUQjD8jvByohVgExTf8ZHaaFhklpzST</div>
<div>TsgM0H0ObX2+lBE/7T5vmfBBXnbKG5YaGEZXiY+iAM/6PSXynfKXArHmj5yE2tq+Kj3GU3SqYt0R</div>
<div>dVkpy5X8pJxp6PPyowh7yNHa3QnqHfqw+v3Hccey9NVI+YNUWPQPpNH2zTVDePajCNSGyMJWFjuI</div>
<div>Cz8zmKXukZZ69mloZtWLmZLAUF1VDXZija/UBxXSAAXEJNH5bt+3VOk80NpGsfhEyhhKBrdrVJeQ</div>
<div>cE4E11ZwgWPMRq27UJQvl39HjfwMRqSIVPUbby3d/tMqduUz1LaPWEgFR85o2xweDTCJAgMBAAGj</div>
<div>ezB5MFgGA1UdEQRRME+CGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1hjFodHRwczovL2lkcHQu</div>
<div>cWF0YXItbWVkLmNvcm5lbGwuZWR1L2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBRTabVogvg9BMur</div>
<div>5/f86IGwgUoYSzANBgkqhkiG9w0BAQUFAAOCAQEANC2iz+LhfSYxEZPprWKGVj3+y2tROJvHhUdf</div>
<div>CwDzJxEMZelOqDF1uLBfzvx51YU/yG7I53MprvN2m+saFKfr2WxTqyLUhaROESwRbSFH97lpLFQT</div>
<div>8Mz3fZR+bhFCfGT3c/BhErZH63r5aZIZRpJm5vCf6UaL2PYpYtiEC2eMl2Sr7iwCYsiCsKds/E0s</div>
<div>PICmT447oOLMzkFSgy1VP9OjAtqoo7xN5TthGfo8hQ9LgoGE6s4faoBu8mJ+OULd8PE7i5WTtQcJ</div>
<div>7++qq3HEvemQ2Y38G66TtbfXEKquXPC62taHiqxW4outfP3OAHSOvE1x648N5GSI+BtjeJIovqdZ</div>
<div>9w==</ds:X509Certificate></div>
<div> </ds:X509Data></div>
<div> </ds:KeyInfo></div>
<div> </ds:Signature></div>
<div> <saml2:Subject></div>
<div> <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="<a href="https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth">https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth</a>" SPNameQualifier="<a href="https://unixadmin.qatar-med.cornell.edu">https://unixadmin.qatar-med.cornell.edu</a>">_e221f54691ae1319a99d6505bb0f6562</saml2:NameID></div>
<div> <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"></div>
<div> <saml2:SubjectConfirmationData Address="207.162.245.59" InResponseTo="_70375afcf2a3ff695a2929bdf8237cda" NotOnOrAfter="2013-11-25T05:14:47.997Z" Recipient="<a href="https://unixadmin.qatar-med.cornell">https://unixadmin.qatar-med.cornell</a>.</div>
<div>
<div>edu/Shibboleth.sso/SAML2/POST"/></div>
</div>
<div><br>
</div>
<div>If I take a chunk of that and search for it on the SP I find that it is in the idp metadata file:</div>
<div>
<div>[root@unixadmin ~]# grep -R BgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTE /etc/shibboleth/</div>
<div>/etc/shibboleth/idp-metadata.xml:BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
<div>/etc/shibboleth/idp-metadata.xml:BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
<div>/etc/shibboleth/partner-metadata.xml: BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
<div>/etc/shibboleth/partner-metadata.xml: BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
<div>/etc/shibboleth/idp-metadata.xml_sam_2013-11-20:BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
<div>/etc/shibboleth/idp-metadata.xml_sam_2013-11-20:BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
</div>
<div><br>
</div>
<div>This is the metadata file specified in shibboleth2.xml:</div>
<div>
<div> <MetadataProvider type="XML" uri="<a href="https://idpt.qatar-med.cornell.edu/idp/profile/Metadata/SAML">https://idpt.qatar-med.cornell.edu/idp/profile/Metadata/SAML</a>"</div>
<div> backingFilePath="idp-metadata.xml" reloadInterval="7200"></div>
<div> </MetadataProvider></div>
</div>
<div><br>
</div>
<div>In going through the debug log it looks to me as if the encoding succeeds:</div>
<div>
<div>08:09:48.513 - DEBUG [org.opensaml.ws.message.encoder.BaseMessageEncoder:56] - Successfully encoded message.</div>
<div>08:09:48.525 - INFO [Shibboleth-Audit:1028] - 20131125T050948Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_70375afcf2a3ff695a2929bdf8237cda|https://unixadmin.qatar-med.cornell.edu|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_5ae8946acd47a082e0a4282246bf3298|saa2012|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||_e221f54691ae1319a99d6505bb0f6562||</div>
</div>
<div><br>
</div>
<div>It is the SP that is not accepting the response somehow:</div>
<div>
<div>2013-11-25 08:09:48 WARN Shibboleth.SSO.SAML2 [2]: detected a problem with assertion: Unable to establish security of incoming assertion.</div>
</div>
<div><br>
</div>
<div>Is there some similar debug logging I can enable on the SP side? There are all of these options about different -- I don't know what to call them -- ways of getting responses (I seem to be using HTTP-POST). I'm not sure if I should be configuring something
there but everything I read suggests to me that I should be able to get things working without customising any of that.</div>
<div><br>
</div>
<div>I feel it is close to success. Hopefully someone can spot where I am going wrong. I can post any logs or configs if they will help.</div>
<div><br>
</div>
<div>Sam</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
<div>
<div>On Nov 24, 2013, at 11:45 AM, Nate Klingenstein wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
Sam,
<div><br>
</div>
<div>
<div>
<blockquote type="cite">
<div style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">
How can I see what key is in the SAML response?</div>
</blockquote>
<div><br>
</div>
<div>The easy way is to turn the Shibboleth SP's shibd.logger to DEBUG and look at shibd.log when an assertion comes in. It will log everything in the response.</div>
<div><br>
</div>
<div>If the response is not encrypted, then you can also look at it in a browser using a tool like SAML tracer for Firefox or even a generic web console.</div>
<div><br>
</div>
<blockquote type="cite">
<div style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">
What can I check to narrow things down?</div>
</blockquote>
</div>
<br>
</div>
<div>The SP's logs will tell you exactly what went wrong. It's likely the keys, as Paul suggested, if your clocks are on.</div>
<div><br>
</div>
<div>Thanks,</div>
<div>Nate.</div>
</div>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></blockquote>
</div>
<br>
<div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; "><br class="Apple-interchange-newline">
--</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Sam Agnew</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
System Administrator</div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">IT Department</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Weill Cornell Medical College in Qatar</font></div>
<div style="font-family: Helvetica; font-size: 12px; "><br class="webkit-block-placeholder">
</div>
<br class="Apple-interchange-newline">
</div>
<br>
</div>
</div>
</body>
</html>