<div dir="ltr">It's also saying this:<div><br></div><div>2015-01-16 22:15:30,519 - DEBUG [net.shibboleth.idp.saml.profile.impl.ExtractSubjectFromRequest:144] - Profile Action ExtractSubjectFromRequest: No Subject NameID or NameIdentifier in message<br></div><div><br></div><div>Perhaps something screwy with the SP?</div><div><br></div><div>Dave</div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Jan 16, 2015 at 10:16 PM, David Langenberg <span dir="ltr"><<a href="mailto:davel@uchicago.edu" target="_blank">davel@uchicago.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Set both of those to true (restarted Jetty, cleared browser), still getting:<div><br></div><div><div>2015-01-16 22:15:30,695 - ERROR [net.shibboleth.idp.saml.saml2.profile.impl.ProcessLogoutRequest:314] - Profile Action ProcessLogoutRequest: Error resolving matching session(s)</div><span class=""><div>net.shibboleth.utilities.java.support.resolver.ResolverException: Secondary service index is disabled</div><div><span style="white-space:pre-wrap">        </span>at net.shibboleth.idp.session.impl.StorageBackedSessionManager.resolve(StorageBackedSessionManager.java:569)</div></span></div><div><br></div><div>and my SAML Error sent back to SP.</div><div><br></div><div>Dave</div></div><div class="gmail_extra"><br><div class="gmail_quote"><div><div class="h5">On Fri, Jan 16, 2015 at 10:08 PM, Tom Zeller <span dir="ltr"><<a href="mailto:tzeller@dragonacea.biz" target="_blank">tzeller@dragonacea.biz</a>></span> wrote:<br></div></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div><div class="h5"><div dir="auto"><div><div><div><br></div><div><br>On Jan 16, 2015, at 11:04 PM, Tom Zeller <<a href="mailto:tzeller@dragonacea.biz" target="_blank">tzeller@dragonacea.biz</a>> wrote:<br><br></div><blockquote type="cite"><div><div><br></div><div><br>On Jan 16, 2015, at 10:23 PM, David Langenberg <<a href="mailto:davel@uchicago.edu" target="_blank">davel@uchicago.edu</a>> wrote:<br><br></div><blockquote type="cite"><div dir="ltr">I have v3 with a fairly default setup. When I initiate a logout request at an SP, the result is a SAML Error being returned to the SP. I see in the logs the logout flow activated and then this:<div><br></div><div><div>2015-01-16 21:09:42,364 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:65] - Profile Action SelectProfileInterceptorFlow: Moving completed flow intercept/security-policy/saml2-slo to completed set, selecting next one</div><div>2015-01-16 21:09:42,365 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:80] - Profile Action SelectProfileInterceptorFlow: No flows available to choose from</div><div>2015-01-16 21:09:42,378 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeOutboundMessageContext:149] - Profile Action InitializeOutboundMessageContext: Initialized outbound message context</div><div>2015-01-16 21:09:42,411 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:367] - Profile Action PopulateBindingAndEndpointContexts: Attempting to resolve endpoint of type {urn:oasis:names:tc:SAML:2.0:metadata}SingleLogoutService for outbound message</div><div>2015-01-16 21:09:42,420 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:409] - Profile Action PopulateBindingAndEndpointContexts: Resolved endpoint at location <a href="https://sp.training.incommon.org/Shibboleth.sso/SLO/Redirect" target="_blank">https://sp.training.incommon.org/Shibboleth.sso/SLO/Redirect</a> using binding urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect</div><div>2015-01-16 21:09:42,465 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:304] - Profile Action PopulateEncryptionParameters: Encryption for assertions (false), identifiers (true), attributes(false)</div><div>2015-01-16 21:09:42,467 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:314] - Profile Action PopulateEncryptionParameters: Resolving EncryptionParameters for request</div><div>2015-01-16 21:09:42,468 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:376] - Profile Action PopulateEncryptionParameters: Adding entityID to resolution criteria</div><div>2015-01-16 21:09:42,469 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:387] - Profile Action PopulateEncryptionParameters: Adding role metadata to resolution criteria</div><div>2015-01-16 21:09:42,471 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:330] - Profile Action PopulateEncryptionParameters: Resolved EncryptionParameters</div><div>2015-01-16 21:09:42,535 - DEBUG [net.shibboleth.idp.saml.profile.impl.ExtractSubjectFromRequest:144] - Profile Action ExtractSubjectFromRequest: No Subject NameID or NameIdentifier in message</div><div>2015-01-16 21:09:42,596 - ERROR [net.shibboleth.idp.saml.saml2.profile.impl.ProcessLogoutRequest:314] - Profile Action ProcessLogoutRequest: Error resolving matching session(s)</div><div>net.shibboleth.utilities.java.support.resolver.ResolverException: Secondary service index is disabled</div><div><span style="white-space:pre-wrap">        </span>at net.shibboleth.idp.session.impl.StorageBackedSessionManager.resolve(StorageBackedSessionManager.java:569)</div><div><br></div><div>Any thoughts on what I may be doing wrong, or should I take this over to JIRA?</div></div></div></blockquote><br><div>There's two session properties in conf/idp.properties that need to be turned true, IIRC. Secondary index and something else nearby.</div></div></blockquote><br></div></div><div>Maybe the other property, besides secondary index, is track sessions.</div></div><br></div></div><span class="HOEnZb"><font color="#888888">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br></font></span></blockquote></div><span class=""><br><br clear="all"><div><br></div>-- <br><div>David Langenberg<div>Identity & Access Management</div><div>The University of Chicago</div></div>
</span></div>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature">David Langenberg<div>Identity & Access Management</div><div>The University of Chicago</div></div>
</div>