<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<pre id="txt">Hi,</pre>
<pre id="txt">I upgraded our test IDP to 3.1.1. During testings, I found one SP stopped working while others worked fine. No error or warning in idp-process.log. There is info level message showing <font face="Menlo"><span style="font-size: 11px;">"None of the potential authentication flows can satisfy the request”. Is this something I can fix in IDP configuration or it has to be fixed in SP? This SP worked fine before the upgrade. </span></font></pre>
<pre id="txt"><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"</pre>
<pre id="txt"> ID="s2318e95b21f623e2ab7a5e276c4b8cf8e0b03f5dc"
Version="2.0"
IssueInstant="2015-04-07T14:04:18Z"
Destination="<a href="https://shibidp-test.cit.cornell.edu/idp/profile/SAML2/Redirect/SSO">https://shibidp-test.cit.cornell.edu/idp/profile/SAML2/Redirect/SSO</a>"
ForceAuthn="false"
IsPassive="false"
ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
AssertionConsumerServiceURL="<a href="https://login-ma-sso.onbmc.com:443/atriumsso/Consumer/metaAlias/cornell-dev/sp">https://login-ma-sso.onbmc.com:443/atriumsso/Consumer/metaAlias/cornell-dev/sp</a>"
>
<saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">sp</saml:Issuer>
<samlp:NameIDPolicy xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
AllowCreate="true"
/>
<samlp:RequestedAuthnContext xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
Comparison="minimum"
>
<saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml:AuthnContextClassRef>
</samlp:RequestedAuthnContext>
</samlp:AuthnRequest></pre>
<div><br>
</div>
<div>
<pre id="txt"><saml2p:Response Destination="<a href="https://login-ma-sso.onbmc.com:443/atriumsso/Consumer/metaAlias/cornell-dev/sp">https://login-ma-sso.onbmc.com:443/atriumsso/Consumer/metaAlias/cornell-dev/sp</a>"
ID="_032a389124ff07af050fe4a658eebba2"
InResponseTo="s265fdd20a8b4f39c82aab327e63a7e91be0772700"
IssueInstant="2015-04-07T14:16:28.214Z"
Version="2.0"
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
>
<saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://shibidp-test.cit.cornell.edu/idp/shibboleth</saml2:Issuer>">https://shibidp-test.cit.cornell.edu/idp/shibboleth</saml2:Issuer></a>
<ds:Signature xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>" />
<ds:SignatureMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>" />
<ds:Reference URI="#_032a389124ff07af050fe4a658eebba2">
<ds:Transforms>
<ds:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>" />
<ds:Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>" />
</ds:Transforms>
<ds:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>" />
<ds:DigestValue>hx3Z5VkioBUDFqq/hqzV2ugFLhr3qNchrfkf5M57q4k=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>
NB/DVSxDUSm/tRn6cgp9fapwQzlpv9Lw07m3Y1JLHI2L2gG6Ja65F/4PsFS4CXum6bcBA8cJOs+d
3+PDxnKUs1N5YGfDMP/w3vdY25MDXiFjwuvJX+J612wD8yt2gBcMfquPIjSlif6+GbjU5alrbdQd
z6JWcmt+W5UeHKuLKpjoWJIBKDr9+ThaaLPHlVQtVn7YA0EpF9Q8GM5MPVvlbf2YT2uXcfSCckT/
rggZiVl74omiVjwnGy5i6ECoIk459Ph9dQTwBuk1ihoSDcEKg/vJYHNh8IZ9UdYnGTGXoFycu2P2
pXJlZn4u2mVpdOeyCbsWc8Spc85KTx7eLEV/Iw==
</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>MIIDXDCCAkSgAwIBAgIVAMKCR8IGXIOzO/yLt6e4sd7OMLgEMA0GCSqGSIb3DQEBBQUAMCcxJTAj
BgNVBAMTHHNoaWJpZHAtdGVzdC5jaXQuY29ybmVsbC5lZHUwHhcNMTIwNjA3MTg0NjIyWhcNMzIw
NjA3MTg0NjIyWjAnMSUwIwYDVQQDExxzaGliaWRwLXRlc3QuY2l0LmNvcm5lbGwuZWR1MIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkhlf9EP399mqnBtGmPG9Vqu79Af2NZhhsT+LTMA1
uhPZYv4RX/E4VD+Iqce/EUP1ndPkGEwBnhrRT2ZegDpCmgo+EcED8cAh9AbwFTTitmBjxvErtJnS
0ZBfMCLDcgOV1zM6bT5fF9SAIm0ZVSaeyQbNDwVDdwsBQHjAdg5vLd5VeYH9MI6enzdgBtPNSrEt
3qZtCWl7ev8YQlWF3vZ+EoyDrWPZSOWzgR31QBs7mz13ABSveIri68FgNth9ylgFS7VNUlAp6xx6
BRnMgL1QzVMZ5F4PbSRDp3UBoS6PMHd+WFenJWPPh6ShMyrInrJ4QAPfKC77tJW+GUXl4T4DqQID
AQABo38wfTBcBgNVHREEVTBTghxzaGliaWRwLXRlc3QuY2l0LmNvcm5lbGwuZWR1hjNodHRwczov
L3NoaWJpZHAtdGVzdC5jaXQuY29ybmVsbC5lZHUvaWRwL3NoaWJib2xldGgwHQYDVR0OBBYEFF9R
ADnmBsO50hD8T+MUFqIgWAOxMA0GCSqGSIb3DQEBBQUAA4IBAQBqYpfdK4XAYE56sYmq/vUKOSBc
bO2Uy3R7oTGrDKxrZI7xC1jchaaTW6BXtg6wzTSn8Jo2M0gvQrWyxZgQDrXGaL2TaPf5WjOWt/Ss
uJ+IShofS6ZWLkPCnrR0Ag9PwU58szw2jjUE4eJyv/dLDzhDHJ0EGastgSzRh1r3v2w8BYz1RHvj
wESPB2HTgV1iuHwaIjaJxN39XyS6ZQzBj6sZ6Lem1R39zXmEvtVfCk9qgSKnbYulrrkIBzxllB34
TUTKFs+Nz1j/sg2gj6Q5u9uW6mSm66mqn2E53r2CNHPTzWGwom5Mi9Z/DtOb2L/5jjxhFvCKxnEb
IWm7XIe8qtqo</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
<saml2p:Status>
<saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Requester">
<saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:NoAuthnContext" />
</saml2p:StatusCode>
<saml2p:StatusMessage>authn</saml2p:StatusMessage>
</saml2p:Status>
</saml2p:Response>
</pre>
<div>Thanks,</div>
</div>
<div>Hong</div>
</body>
</html>