<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<pre id="txt">Hi,</pre>
<pre id="txt">I upgraded our test IDP to 3.1.1. During testings, I found one SP stopped working while others worked fine. No error or warning in idp-process.log. There is info level message showing <font face="Menlo"><span style="font-size: 11px;">&quot;None of the potential authentication flows can satisfy the request”. Is this something I can fix in IDP configuration or it has to be fixed in SP? This SP worked fine before the upgrade. </span></font></pre>
<pre id="txt">&lt;samlp:AuthnRequest xmlns:samlp=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot;</pre>
<pre id="txt">                    ID=&quot;s2318e95b21f623e2ab7a5e276c4b8cf8e0b03f5dc&quot;
                    Version=&quot;2.0&quot;
                    IssueInstant=&quot;2015-04-07T14:04:18Z&quot;
                    Destination=&quot;<a href="https://shibidp-test.cit.cornell.edu/idp/profile/SAML2/Redirect/SSO">https://shibidp-test.cit.cornell.edu/idp/profile/SAML2/Redirect/SSO</a>&quot;
                    ForceAuthn=&quot;false&quot;
                    IsPassive=&quot;false&quot;
                    ProtocolBinding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot;
                    AssertionConsumerServiceURL=&quot;<a href="https://login-ma-sso.onbmc.com:443/atriumsso/Consumer/metaAlias/cornell-dev/sp">https://login-ma-sso.onbmc.com:443/atriumsso/Consumer/metaAlias/cornell-dev/sp</a>&quot;
                    &gt;
    &lt;saml:Issuer xmlns:saml=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot;&gt;sp&lt;/saml:Issuer&gt;
    &lt;samlp:NameIDPolicy xmlns:samlp=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot;
                        Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&quot;
                        AllowCreate=&quot;true&quot;
                        /&gt;
    &lt;samlp:RequestedAuthnContext xmlns:samlp=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot;
                                 Comparison=&quot;minimum&quot;
                                 &gt;
        &lt;saml:AuthnContextClassRef xmlns:saml=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot;&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified&lt;/saml:AuthnContextClassRef&gt;
    &lt;/samlp:RequestedAuthnContext&gt;
&lt;/samlp:AuthnRequest&gt;</pre>
<div><br>
</div>
<div>
<pre id="txt">&lt;saml2p:Response Destination=&quot;<a href="https://login-ma-sso.onbmc.com:443/atriumsso/Consumer/metaAlias/cornell-dev/sp">https://login-ma-sso.onbmc.com:443/atriumsso/Consumer/metaAlias/cornell-dev/sp</a>&quot;
                 ID=&quot;_032a389124ff07af050fe4a658eebba2&quot;
                 InResponseTo=&quot;s265fdd20a8b4f39c82aab327e63a7e91be0772700&quot;
                 IssueInstant=&quot;2015-04-07T14:16:28.214Z&quot;
                 Version=&quot;2.0&quot;
                 xmlns:saml2p=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot;
                 &gt;
    &lt;saml2:Issuer xmlns:saml2=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot;&gt;<a href="https://shibidp-test.cit.cornell.edu/idp/shibboleth&lt;/saml2:Issuer&gt;">https://shibidp-test.cit.cornell.edu/idp/shibboleth&lt;/saml2:Issuer&gt;</a>
    &lt;ds:Signature xmlns:ds=&quot;<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>&quot;&gt;
        &lt;ds:SignedInfo&gt;
            &lt;ds:CanonicalizationMethod Algorithm=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot; /&gt;
            &lt;ds:SignatureMethod Algorithm=&quot;<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>&quot; /&gt;
            &lt;ds:Reference URI=&quot;#_032a389124ff07af050fe4a658eebba2&quot;&gt;
                &lt;ds:Transforms&gt;
                    &lt;ds:Transform Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>&quot; /&gt;
                    &lt;ds:Transform Algorithm=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot; /&gt;
                &lt;/ds:Transforms&gt;
                &lt;ds:DigestMethod Algorithm=&quot;<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>&quot; /&gt;
                &lt;ds:DigestValue&gt;hx3Z5VkioBUDFqq/hqzV2ugFLhr3qNchrfkf5M57q4k=&lt;/ds:DigestValue&gt;
            &lt;/ds:Reference&gt;
        &lt;/ds:SignedInfo&gt;
        &lt;ds:SignatureValue&gt;
NB/DVSxDUSm/tRn6cgp9fapwQzlpv9Lw07m3Y1JLHI2L2gG6Ja65F/4PsFS4CXum6bcBA8cJOs&#43;d
3&#43;PDxnKUs1N5YGfDMP/w3vdY25MDXiFjwuvJX&#43;J612wD8yt2gBcMfquPIjSlif6&#43;GbjU5alrbdQd
z6JWcmt&#43;W5UeHKuLKpjoWJIBKDr9&#43;ThaaLPHlVQtVn7YA0EpF9Q8GM5MPVvlbf2YT2uXcfSCckT/
rggZiVl74omiVjwnGy5i6ECoIk459Ph9dQTwBuk1ihoSDcEKg/vJYHNh8IZ9UdYnGTGXoFycu2P2
pXJlZn4u2mVpdOeyCbsWc8Spc85KTx7eLEV/Iw==
&lt;/ds:SignatureValue&gt;
        &lt;ds:KeyInfo&gt;
            &lt;ds:X509Data&gt;
                &lt;ds:X509Certificate&gt;MIIDXDCCAkSgAwIBAgIVAMKCR8IGXIOzO/yLt6e4sd7OMLgEMA0GCSqGSIb3DQEBBQUAMCcxJTAj
BgNVBAMTHHNoaWJpZHAtdGVzdC5jaXQuY29ybmVsbC5lZHUwHhcNMTIwNjA3MTg0NjIyWhcNMzIw
NjA3MTg0NjIyWjAnMSUwIwYDVQQDExxzaGliaWRwLXRlc3QuY2l0LmNvcm5lbGwuZWR1MIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkhlf9EP399mqnBtGmPG9Vqu79Af2NZhhsT&#43;LTMA1
uhPZYv4RX/E4VD&#43;Iqce/EUP1ndPkGEwBnhrRT2ZegDpCmgo&#43;EcED8cAh9AbwFTTitmBjxvErtJnS
0ZBfMCLDcgOV1zM6bT5fF9SAIm0ZVSaeyQbNDwVDdwsBQHjAdg5vLd5VeYH9MI6enzdgBtPNSrEt
3qZtCWl7ev8YQlWF3vZ&#43;EoyDrWPZSOWzgR31QBs7mz13ABSveIri68FgNth9ylgFS7VNUlAp6xx6
BRnMgL1QzVMZ5F4PbSRDp3UBoS6PMHd&#43;WFenJWPPh6ShMyrInrJ4QAPfKC77tJW&#43;GUXl4T4DqQID
AQABo38wfTBcBgNVHREEVTBTghxzaGliaWRwLXRlc3QuY2l0LmNvcm5lbGwuZWR1hjNodHRwczov
L3NoaWJpZHAtdGVzdC5jaXQuY29ybmVsbC5lZHUvaWRwL3NoaWJib2xldGgwHQYDVR0OBBYEFF9R
ADnmBsO50hD8T&#43;MUFqIgWAOxMA0GCSqGSIb3DQEBBQUAA4IBAQBqYpfdK4XAYE56sYmq/vUKOSBc
bO2Uy3R7oTGrDKxrZI7xC1jchaaTW6BXtg6wzTSn8Jo2M0gvQrWyxZgQDrXGaL2TaPf5WjOWt/Ss
uJ&#43;IShofS6ZWLkPCnrR0Ag9PwU58szw2jjUE4eJyv/dLDzhDHJ0EGastgSzRh1r3v2w8BYz1RHvj
wESPB2HTgV1iuHwaIjaJxN39XyS6ZQzBj6sZ6Lem1R39zXmEvtVfCk9qgSKnbYulrrkIBzxllB34
TUTKFs&#43;Nz1j/sg2gj6Q5u9uW6mSm66mqn2E53r2CNHPTzWGwom5Mi9Z/DtOb2L/5jjxhFvCKxnEb
IWm7XIe8qtqo&lt;/ds:X509Certificate&gt;
            &lt;/ds:X509Data&gt;
        &lt;/ds:KeyInfo&gt;
    &lt;/ds:Signature&gt;
    &lt;saml2p:Status&gt;
        &lt;saml2p:StatusCode Value=&quot;urn:oasis:names:tc:SAML:2.0:status:Requester&quot;&gt;
            &lt;saml2p:StatusCode Value=&quot;urn:oasis:names:tc:SAML:2.0:status:NoAuthnContext&quot; /&gt;
        &lt;/saml2p:StatusCode&gt;
        &lt;saml2p:StatusMessage&gt;authn&lt;/saml2p:StatusMessage&gt;
    &lt;/saml2p:Status&gt;
&lt;/saml2p:Response&gt;
</pre>
<div>Thanks,</div>
</div>
<div>Hong</div>
</body>
</html>