<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
OK, figured out debug logging on SP. Here is the debug version of the SP side of it. Again, looks like it decrypts message OK but doesn't know what to do with it:
<div><br>
</div>
<div>
<div>2013-11-25 12:05:36 DEBUG OpenSAML.MessageDecoder.SAML2 [2]: message from (<a href="https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth">https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth</a>)</div>
<div>2013-11-25 12:05:36 DEBUG OpenSAML.MessageDecoder.SAML2 [2]: searching metadata for message issuer...</div>
<div>2013-11-25 12:05:36 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2]: evaluating message flow policy (replay checking on, expiration 60)</div>
<div>2013-11-25 12:05:36 DEBUG XMLTooling.StorageService [2]: inserted record (_80f4c1df42380fb62acfa6dfce839b31) in context (MessageFlow) with expiration (1385370575)</div>
<div>2013-11-25 12:05:36 DEBUG Shibboleth.SSO.SAML2 [2]: processing message against SAML 2.0 SSO profile</div>
<div>2013-11-25 12:05:36 DEBUG XMLTooling.CredentialCriteria [2]: key algorithm didn't match ('AES' != 'RSA')</div>
<div>2013-11-25 12:05:36 DEBUG Shibboleth.SSO.SAML2 [2]: decrypted Assertion: <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_4d16eaa7eb0a62bd986db112e23330ec" IssueInstant="2013-11-25T09:05:35.906Z" Version="2.0"><saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth</saml2:Issuer><ds:Signature
xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"><ds:SignedInfo><ds:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/><ds:SignatureMethod
Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>"/><ds:Reference URI="#_4d16eaa7eb0a62bd986db112e23330ec"><ds:Transforms><ds:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/><ds:Transform
Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/></ds:Transforms><ds:DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>"/><ds:DigestValue>TO8z+MRVauzVnq8vagmo2zDykdo=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>jIbFxjk77RF0Q16aLfSL/xieGKIucO5/Jo6cUEGIEdE+iDaUSdr6v5UWRim+oHKldM/iqwgDh2wonWww6dLnr9T0bdAJfd4RwC9a9w3SjYorfCL0lul5Rl3z0TIds5eL7phIieZEy8B13GVkoW4KtCCAqFi4KkRssXicE7dQenEa/b6uquI31+gMaTdW58iU6R0JYBE3zlXbe9cwKdC0wKtIHVNkEwtxb0LaUEWqo2UJxKp46JxDNHWQL6sJWlc+ZJoMFZG+xmT/KY/Iu663xyLMOGRTr+zBi7Spemhgf48rLhpyDUkdP6fW8qVOEms74zSfCF3HR1K9DBrpeIbgIA==</ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate>MIIDVDCCAjygAwIBAgIVAJ8yKHKyn+jtv2SGeaU0ssFAVLaYMA0GCSqGSIb3DQEBBQUAMCUxIzAh</div>
<div>BgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEzMTExNDA1MzIwNloXDTMzMTEx</div>
<div>NDA1MzIwNlowJTEjMCEGA1UEAxMaaWRwdC5xYXRhci1tZWQuY29ybmVsbC5lZHUwggEiMA0GCSqG</div>
<div>SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+Oo5QLdGh0Y4OrLUQjD8jvByohVgExTf8ZHaaFhklpzST</div>
<div>TsgM0H0ObX2+lBE/7T5vmfBBXnbKG5YaGEZXiY+iAM/6PSXynfKXArHmj5yE2tq+Kj3GU3SqYt0R</div>
<div>dVkpy5X8pJxp6PPyowh7yNHa3QnqHfqw+v3Hccey9NVI+YNUWPQPpNH2zTVDePajCNSGyMJWFjuI</div>
<div>Cz8zmKXukZZ69mloZtWLmZLAUF1VDXZija/UBxXSAAXEJNH5bt+3VOk80NpGsfhEyhhKBrdrVJeQ</div>
<div>cE4E11ZwgWPMRq27UJQvl39HjfwMRqSIVPUbby3d/tMqduUz1LaPWEgFR85o2xweDTCJAgMBAAGj</div>
<div>ezB5MFgGA1UdEQRRME+CGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1hjFodHRwczovL2lkcHQu</div>
<div>cWF0YXItbWVkLmNvcm5lbGwuZWR1L2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBRTabVogvg9BMur</div>
<div>5/f86IGwgUoYSzANBgkqhkiG9w0BAQUFAAOCAQEANC2iz+LhfSYxEZPprWKGVj3+y2tROJvHhUdf</div>
<div>CwDzJxEMZelOqDF1uLBfzvx51YU/yG7I53MprvN2m+saFKfr2WxTqyLUhaROESwRbSFH97lpLFQT</div>
<div>8Mz3fZR+bhFCfGT3c/BhErZH63r5aZIZRpJm5vCf6UaL2PYpYtiEC2eMl2Sr7iwCYsiCsKds/E0s</div>
<div>PICmT447oOLMzkFSgy1VP9OjAtqoo7xN5TthGfo8hQ9LgoGE6s4faoBu8mJ+OULd8PE7i5WTtQcJ</div>
<div>7++qq3HEvemQ2Y38G66TtbfXEKquXPC62taHiqxW4outfP3OAHSOvE1x648N5GSI+BtjeJIovqdZ</div>
<div>9w==</ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature><saml2:Subject><saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="<a href="https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth">https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth</a>"
SPNameQualifier="<a href="https://unixadmin.qatar-med.cornell.edu">https://unixadmin.qatar-med.cornell.edu</a>">_8447b609ae9fcdb3b780a3bf49ade90b</saml2:NameID><saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml2:SubjectConfirmationData
Address="207.162.244.209" InResponseTo="_d9393154b17020f6044a0a70eefff6aa" NotOnOrAfter="2013-11-25T09:10:35.906Z" Recipient="<a href="https://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST">https://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST</a>"/></saml2:SubjectConfirmation></saml2:Subject><saml2:Conditions
NotBefore="2013-11-25T09:05:35.906Z" NotOnOrAfter="2013-11-25T09:10:35.906Z"><saml2:AudienceRestriction><saml2:Audience>https://unixadmin.qatar-med.cornell.edu</saml2:Audience></saml2:AudienceRestriction></saml2:Conditions><saml2:AuthnStatement AuthnInstant="2013-11-25T09:05:35.761Z"
SessionIndex="_815ce11ee2b19d24679a898219ffcdc0"><saml2:SubjectLocality Address="207.162.244.209"/><saml2:AuthnContext><saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef></saml2:AuthnContext></saml2:AuthnStatement></saml2:Assertion></div>
<div>2013-11-25 12:05:36 DEBUG Shibboleth.SSO.SAML2 [2]: extracting issuer from SAML 2.0 assertion</div>
<div>2013-11-25 12:05:36 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2]: evaluating message flow policy (replay checking on, expiration 60)</div>
<div>2013-11-25 12:05:36 DEBUG XMLTooling.StorageService [2]: inserted record (_4d16eaa7eb0a62bd986db112e23330ec) in context (MessageFlow) with expiration (1385370575)</div>
<div>2013-11-25 12:05:36 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [2]: assertion satisfied bearer confirmation requirements</div>
<div>2013-11-25 12:05:36 WARN Shibboleth.SSO.SAML2 [2]: detected a problem with assertion: Unable to establish security of incoming assertion.</div>
<div><br>
</div>
<div><br>
</div>
<div>
<div>On Nov 25, 2013, at 8:46 AM, Sam Agnew wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
I turned on debug logging for IDP. I see a certificate sent in the exchange. It seems to be the right one. I see this cert in the SAML response from my IDP (idpt):
<div><br>
</div>
<div>
<div> <ds:SignatureValue>ZKwMuET4qDGL2CdwIuOjJOpz1QuMNWZvcew+AnsgBJB6znL19zdCAVBBuScMhqJ8OQJynZBmskp5xhxS9Gnr0GEfr9eLcHh+GBP3eSrjoaMwhPznUSrBe84KIwSZNPexVgf7egCS/c05c+v7RK2xrcDs33I6qcVTxPF+6i0ViM5cLP7RMRkvqKOJ82jSEk8zPxUQhlzd7AwJY4YIBFe84fYidfNxWxqdop8iOglUScJ2R0Tl1NtzsZUCL7oVf65tU9sPoD3TmSbbbvvNw84AxPIE5tgrANGxCAs8uSyI1KnesdTlorta3Z+DzlkFlg8TaIwwkZL2zvoXC+0dGrrG5Q==</ds:SignatureValue></div>
<div> <ds:KeyInfo></div>
<div> <ds:X509Data></div>
<div> <ds:X509Certificate>MIIDVDCCAjygAwIBAgIVAJ8yKHKyn+jtv2SGeaU0ssFAVLaYMA0GCSqGSIb3DQEBBQUAMCUxIzAh</div>
<div>BgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEzMTExNDA1MzIwNloXDTMzMTEx</div>
<div>NDA1MzIwNlowJTEjMCEGA1UEAxMaaWRwdC5xYXRhci1tZWQuY29ybmVsbC5lZHUwggEiMA0GCSqG</div>
<div>SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC+Oo5QLdGh0Y4OrLUQjD8jvByohVgExTf8ZHaaFhklpzST</div>
<div>TsgM0H0ObX2+lBE/7T5vmfBBXnbKG5YaGEZXiY+iAM/6PSXynfKXArHmj5yE2tq+Kj3GU3SqYt0R</div>
<div>dVkpy5X8pJxp6PPyowh7yNHa3QnqHfqw+v3Hccey9NVI+YNUWPQPpNH2zTVDePajCNSGyMJWFjuI</div>
<div>Cz8zmKXukZZ69mloZtWLmZLAUF1VDXZija/UBxXSAAXEJNH5bt+3VOk80NpGsfhEyhhKBrdrVJeQ</div>
<div>cE4E11ZwgWPMRq27UJQvl39HjfwMRqSIVPUbby3d/tMqduUz1LaPWEgFR85o2xweDTCJAgMBAAGj</div>
<div>ezB5MFgGA1UdEQRRME+CGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1hjFodHRwczovL2lkcHQu</div>
<div>cWF0YXItbWVkLmNvcm5lbGwuZWR1L2lkcC9zaGliYm9sZXRoMB0GA1UdDgQWBBRTabVogvg9BMur</div>
<div>5/f86IGwgUoYSzANBgkqhkiG9w0BAQUFAAOCAQEANC2iz+LhfSYxEZPprWKGVj3+y2tROJvHhUdf</div>
<div>CwDzJxEMZelOqDF1uLBfzvx51YU/yG7I53MprvN2m+saFKfr2WxTqyLUhaROESwRbSFH97lpLFQT</div>
<div>8Mz3fZR+bhFCfGT3c/BhErZH63r5aZIZRpJm5vCf6UaL2PYpYtiEC2eMl2Sr7iwCYsiCsKds/E0s</div>
<div>PICmT447oOLMzkFSgy1VP9OjAtqoo7xN5TthGfo8hQ9LgoGE6s4faoBu8mJ+OULd8PE7i5WTtQcJ</div>
<div>7++qq3HEvemQ2Y38G66TtbfXEKquXPC62taHiqxW4outfP3OAHSOvE1x648N5GSI+BtjeJIovqdZ</div>
<div>9w==</ds:X509Certificate></div>
<div> </ds:X509Data></div>
<div> </ds:KeyInfo></div>
<div> </ds:Signature></div>
<div> <saml2:Subject></div>
<div> <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="<a href="https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth">https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth</a>" SPNameQualifier="<a href="https://unixadmin.qatar-med.cornell.edu/">https://unixadmin.qatar-med.cornell.edu</a>">_e221f54691ae1319a99d6505bb0f6562</saml2:NameID></div>
<div> <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"></div>
<div> <saml2:SubjectConfirmationData Address="207.162.245.59" InResponseTo="_70375afcf2a3ff695a2929bdf8237cda" NotOnOrAfter="2013-11-25T05:14:47.997Z" Recipient="<a href="https://unixadmin.qatar-med.cornell/">https://unixadmin.qatar-med.cornell</a>.</div>
<div>
<div>edu/Shibboleth.sso/SAML2/POST"/></div>
</div>
<div><br>
</div>
<div>If I take a chunk of that and search for it on the SP I find that it is in the idp metadata file:</div>
<div>
<div>[root@unixadmin ~]# grep -R BgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTE /etc/shibboleth/</div>
<div>/etc/shibboleth/idp-metadata.xml:BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
<div>/etc/shibboleth/idp-metadata.xml:BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
<div>/etc/shibboleth/partner-metadata.xml: BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
<div>/etc/shibboleth/partner-metadata.xml: BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
<div>/etc/shibboleth/idp-metadata.xml_sam_2013-11-20:BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
<div>/etc/shibboleth/idp-metadata.xml_sam_2013-11-20:BQUAMCUxIzAhBgNVBAMTGmlkcHQucWF0YXItbWVkLmNvcm5lbGwuZWR1MB4XDTEz</div>
</div>
<div><br>
</div>
<div>This is the metadata file specified in shibboleth2.xml:</div>
<div>
<div> <MetadataProvider type="XML" uri="<a href="https://idpt.qatar-med.cornell.edu/idp/profile/Metadata/SAML">https://idpt.qatar-med.cornell.edu/idp/profile/Metadata/SAML</a>"</div>
<div> backingFilePath="idp-metadata.xml" reloadInterval="7200"></div>
<div> </MetadataProvider></div>
</div>
<div><br>
</div>
<div>In going through the debug log it looks to me as if the encoding succeeds:</div>
<div>
<div>08:09:48.513 - DEBUG [org.opensaml.ws.message.encoder.BaseMessageEncoder:56] - Successfully encoded message.</div>
<div>08:09:48.525 - INFO [Shibboleth-Audit:1028] - 20131125T050948Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_70375afcf2a3ff695a2929bdf8237cda|https://unixadmin.qatar-med.cornell.edu|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://idpt.qatar-med.cornell.edu:8443/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_5ae8946acd47a082e0a4282246bf3298|saa2012|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||_e221f54691ae1319a99d6505bb0f6562||</div>
</div>
<div><br>
</div>
<div>It is the SP that is not accepting the response somehow:</div>
<div>
<div>2013-11-25 08:09:48 WARN Shibboleth.SSO.SAML2 [2]: detected a problem with assertion: Unable to establish security of incoming assertion.</div>
</div>
<div><br>
</div>
<div>Is there some similar debug logging I can enable on the SP side? There are all of these options about different -- I don't know what to call them -- ways of getting responses (I seem to be using HTTP-POST). I'm not sure if I should be configuring something
there but everything I read suggests to me that I should be able to get things working without customising any of that.</div>
<div><br>
</div>
<div>I feel it is close to success. Hopefully someone can spot where I am going wrong. I can post any logs or configs if they will help.</div>
<div><br>
</div>
<div>Sam</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
<div>
<div>On Nov 24, 2013, at 11:45 AM, Nate Klingenstein wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
Sam,
<div><br>
</div>
<div>
<div>
<blockquote type="cite">
<div style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">
How can I see what key is in the SAML response?</div>
</blockquote>
<div><br>
</div>
<div>The easy way is to turn the Shibboleth SP's shibd.logger to DEBUG and look at shibd.log when an assertion comes in. It will log everything in the response.</div>
<div><br>
</div>
<div>If the response is not encrypted, then you can also look at it in a browser using a tool like SAML tracer for Firefox or even a generic web console.</div>
<div><br>
</div>
<blockquote type="cite">
<div style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">
What can I check to narrow things down?</div>
</blockquote>
</div>
<br>
</div>
<div>The SP's logs will tell you exactly what went wrong. It's likely the keys, as Paul suggested, if your clocks are on.</div>
<div><br>
</div>
<div>Thanks,</div>
<div>Nate.</div>
</div>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></blockquote>
</div>
<br>
<div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; "><br class="Apple-interchange-newline">
--</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Sam Agnew</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
System Administrator</div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">IT Department</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Weill Cornell Medical College in Qatar</font></div>
<div style="font-family: Helvetica; font-size: 12px; "><br class="webkit-block-placeholder">
</div>
<br class="Apple-interchange-newline">
</div>
<br>
</div>
</div>
</div>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></blockquote>
</div>
<br>
<div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; "><br class="Apple-interchange-newline">
--</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Sam Agnew</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
System Administrator</div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">IT Department</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Weill Cornell Medical College in Qatar</font></div>
<div style="font-family: Helvetica; font-size: 12px; "><br class="webkit-block-placeholder">
</div>
<br class="Apple-interchange-newline">
</div>
<br>
</div>
</body>
</html>