<div dir="ltr">The Duo support for the MCB is here:<div><br></div><div><a href="https://github.com/uchicago/mcb-duo">https://github.com/uchicago/mcb-duo</a><br></div><div><br></div><div>and also linked to from </div><div><br></div><div><a href="https://wiki.shibboleth.net/confluence/pages/viewpage.action?pageId=14876757">https://wiki.shibboleth.net/confluence/pages/viewpage.action?pageId=14876757</a><br></div><div><br></div><div>Dave</div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Dec 1, 2014 at 7:48 AM, Steven Carmody <span dir="ltr"><<a href="mailto:steven_carmody@brown.edu" target="_blank">steven_carmody@brown.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi,<br>
<br>
I rebuilt the IDP, from scratch, adding back in the DUO support and the<br>
MCB support. This time it works (sorta, see below). I'm not going to<br>
worry (yet) about last week's problems. ;-)<br>
<br>
However, the IDP sent an authN failed msg to the SP:<br>
<br>
> Unable to satisfy requested authentication context<br>
<br>
I'm not sure why .... I see:<br>
<br>
> Using [brownAuthenticationProfiles] for attribute-resolver ID value.<br>
<br>
and<br>
<br>
> LDAP data connector brownLDAP - Found the following attribute:<br>
brownAuthenticationProfiles[<a href="http://brown.edu/duo" target="_blank">http://brown.edu/duo</a>,<br>
urn:oasis:names:tc:SAML:2.0:ac:classes:Password]<br>
<br>
But, the long list of "Resolved attribute" lines in the idp-process log<br>
file does NOT contain any lines for brownAuthenticationProfiles -- that<br>
makes sense, because I didn't add an AttributeDefinition to the<br>
Attr-bute-resolver file for that ldap attribute.<br>
<br>
Then there's a bunch of lines put out by MCBAttributeResolver,<br>
describing the attributes that it found... that list does NOT include<br>
brownAuthenticationProfiles ...<br>
<br>
and then MCBLoginServlet starts running, and reports:<br>
<br>
> Found idms attribute: null<br>
> Found [0] values in attribute.<br>
> > User [stc] used a context NOT on the potential context list. They<br>
must re-authenticate with a valid context.<br>
<br>
So, before I change something ... I'm guessing I need to add an<br>
AttributeDefinition for the ldap attribute containing the profiles<br>
available for this user ?<br>
<br>
And ... one last question -- I seem to remember that David L developed<br>
some glue code between the MCB and DUO -- however, I can't find it --<br>
where do I go to download that ?<br>
<br>
Thanks !<br>
<span class="HOEnZb"><font color="#888888"><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature">David Langenberg<div>Identity & Access Management</div><div>The University of Chicago</div></div>
</div>