<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:x="urn:schemas-microsoft-com:office:excel" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri","sans-serif";
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">Hi,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"> I’m running some testing on the IDP with MCB. I noticed that when I’m directed to the IDP login page and I simply don’t login and just refresh the page, the MCB regards this as an SSO session and tries to query LDAP using
a null user. This fails of course. But it also increments the failed login count. The odd thing is in the logs, it shows that there was actually no previous session found, but the MCB still thinks it is SSO. Is this the place to be reporting possible
MCB bugs?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">BTW, here’s what I see in the logs when I refresh the login page.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">14:33:19.675 - INFO [Shibboleth-Access:73] - 20150428T183319Z|130.64.204.178|<IDP>:443|/profile/SAML2/Redirect/SSO|<o:p></o:p></p>
<p class="MsoNormal">14:33:19.744 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginHandler:92] - MCBConfiguration bean = [edu.internet2.middleware.assurance.mcb.authn.provider.MCBConfiguration@67c04226]<o:p></o:p></p>
<p class="MsoNormal">14:33:19.745 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginHandler:106] - Relying party = [<SP>]<o:p></o:p></p>
<p class="MsoNormal">14:33:19.745 - TRACE [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginHandler:248] - No session found. Previous Session Support setting = [true]<o:p></o:p></p>
<p class="MsoNormal">14:33:19.745 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginHandler:280] - Redirecting to https://<IDP>/idp/Authn/MCB<o:p></o:p></p>
<p class="MsoNormal">14:33:19.805 - TRACE [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:119] - =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+<o:p></o:p></p>
<p class="MsoNormal">14:33:19.805 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:120] - Request received from [130.64.204.178]<o:p></o:p></p>
<p class="MsoNormal">14:33:19.805 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:128] - principal = [{MCBUsernamePrincipal}[principal]]<o:p></o:p></p>
<p class="MsoNormal">14:33:19.806 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:137] - Relying party = [<SP>]<o:p></o:p></p>
<p class="MsoNormal">14:33:19.806 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:170] - Performing authentication for request.<o:p></o:p></p>
<p class="MsoNormal">14:33:19.806 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:207] - Found 2nd leg of authentication, performing authentication.<o:p></o:p></p>
<p class="MsoNormal">14:33:19.807 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:806] - Getting requested contexts for relying party = [<SP>]<o:p></o:p></p>
<p class="MsoNormal">14:33:19.807 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.JAASLoginSubmodule:244] - Attempting to authenticate user null<o:p></o:p></p>
<p class="MsoNormal">14:33:19.819 - TRACE [edu.vt.middleware.ldap.jaas.LdapLoginModule:144] - Begin initialize<o:p></o:p></p>
<p class="MsoNormal">.<o:p></o:p></p>
<p class="MsoNormal">.<o:p></o:p></p>
<p class="MsoNormal">.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal">-PQ<o:p></o:p></p>
</div>
</body>
</html>