<div dir="ltr"><div>I'm getting the following in debug:</div><div><br></div><div>[Thu Jun 11 13:50:52 2015] [info] Initial (No.1) HTTPS request received for child 0 (server <a href="http://cas.sou.edu:443">cas.sou.edu:443</a>)</div><div>[Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(1745): [client 140.211.91.96] Entering cas_authenticate(), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a></div><div>[Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(607): [client 140.211.91.96] Modified r->args (old 'ticket=ST-1434055852427-bjIkFqajBP0IVHqJfUbxUY0GA', new ''), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a></div><div>[Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(1600): [client 140.211.91.96] entering getResponseFromServer(), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a></div><div>[Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(519): [client 140.211.91.96] entering getCASService(), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a></div><div>[Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(539): [client 140.211.91.96] CAS Service 'https%3a%2f%<a href="http://2fcas.sou.edu">2fcas.sou.edu</a>%2fsecure%2f', referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a></div><div><span style="background-color:rgb(255,255,0)">[Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(1666): [client 140.211.91.96] MOD_AUTH_CAS: curl_easy_perform() failed (Peer certificate cannot be authenticated with known CA certificates), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a></span></div><div>[Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(1293): [client 140.211.91.96] entering isValidCASTicket(), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a></div><div>[Thu Jun 11 13:50:52 2015] [debug] ssl_engine_kernel.c(1863): OpenSSL: Write: SSL negotiation finished successfully</div><div>[Thu Jun 11 13:50:52 2015] [info] [client 140.211.91.96] Connection closed to child 0 with standard shutdown (server <a href="http://cas.sou.edu:443">cas.sou.edu:443</a>)</div><div><br></div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><span style="font-size:12.8000001907349px"><b><br></b></span></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><span style="font-size:12.8000001907349px"><b>Jesse Martinich</b></span></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)">Systems Administrator</div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1">Southern Oregon University</font><span style="font-size:12.8000001907349px"> </span><font size="1">| 1250 Siskiyou Blvd </font><font size="1">| Ashland OR  97520</font><br></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1">541-552-8424</font></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><br></font></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><img src="https://docs.google.com/uc?export=download&id=0BwKjt2yacqt7UkNnWGxXaS1VUzQ&revid=0BwKjt2yacqt7bm9QbWZ5ejBHUWdZeGhGZ0VGWFVLTHFHb21BPQ"><br></font></div><div style="font-size:12.8000001907349px"><font size="1"><font color="#888888">Why I'm at SOU: <a href="https://www.youtube.com/watch?v=Ski0MzPd5IM" style="color:rgb(17,85,204)" target="_blank">https://www.youtube.com/watch?v=Ski0MzPd5IM</a></font></font></div></div></div></div></div></div></div></div></div>
<br><div class="gmail_quote">On Thu, Jun 11, 2015 at 1:46 PM, Jesse Martinich <span dir="ltr"><<a href="mailto:martinicj@sou.edu" target="_blank">martinicj@sou.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">I previously overlooked the lack of debug messages. I had not changed the LogLevel in my vhost to debug, so it was still at warn. I am now seeing a cert issue, looks like I am trusting the Web SSL cert but not the IDP cert.<div><br></div><div>Will update after attempting fix.</div><div><br></div><div>Thanks!</div><span class="HOEnZb"><font color="#888888"><div>Jesse</div></font></span></div><div class="gmail_extra"><span class=""><br clear="all"><div><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><span style="font-size:12.8000001907349px"><b><br></b></span></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><span style="font-size:12.8000001907349px"><b>Jesse Martinich</b></span></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)">Systems Administrator</div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1">Southern Oregon University</font><span style="font-size:12.8000001907349px"> </span><font size="1">| 1250 Siskiyou Blvd </font><font size="1">| Ashland OR  97520</font><br></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><a href="tel:541-552-8424" value="+15415528424" target="_blank">541-552-8424</a></font></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><br></font></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><img src="https://docs.google.com/uc?export=download&id=0BwKjt2yacqt7UkNnWGxXaS1VUzQ&revid=0BwKjt2yacqt7bm9QbWZ5ejBHUWdZeGhGZ0VGWFVLTHFHb21BPQ"><br></font></div><div style="font-size:12.8000001907349px"><font size="1"><font color="#888888">Why I'm at SOU: <a href="https://www.youtube.com/watch?v=Ski0MzPd5IM" style="color:rgb(17,85,204)" target="_blank">https://www.youtube.com/watch?v=Ski0MzPd5IM</a></font></font></div></div></div></div></div></div></div></div></div>
<br></span><div><div class="h5"><div class="gmail_quote">On Thu, Jun 11, 2015 at 1:35 PM, Walter Forbes Hoehn (wassa) <span dir="ltr"><<a href="mailto:wassa@memphis.edu" target="_blank">wassa@memphis.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Ditto what Marvin said below.  You are going to have to check the client end.  The only additional information I’ll add is that every time I’ve seen this in the past it has been one of two things:<br>
<br>
1)  The CAS client was rejecting the CAS server SSL certificate<br>
<br>
2) The CAS client was very old and was not parsing the SOAP envelope correctly.  This was with the CAS client for Java, so it probably doesn’t apply.<br>
<br>
Firewall issues probably don’t come into play all that often, because most folks are running CAS back-channel requests on port 443 along with the /login endpoint.<br>
<span><font color="#888888"><br>
-Walter<br>
</font></span><span><br>
<br>
> On Jun 11, 2015, at 3:23 PM, Marvin Addison <<a href="mailto:marvin.addison@gmail.com" target="_blank">marvin.addison@gmail.com</a>> wrote:<br>
><br>
> 140.211.91.96 - - [11/Jun/2015:12:58:30 -0700] "POST /idp/profile/cas/login;jsessionid=85B70E3AD0AEF47512F7D2D787BEBDCC?execution=e1s1 HTTP/1.1" 302 -<br>
><br>
> The request to /idp/profile/cas/samlValidate to validate the ticket ought to follow shortly after the credential submission above. I think we need to focus on mod_auth_cas debug output in the Apache error log. What does it say?<br>
<br>
</span><div><div>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></div></div></blockquote></div><br></div></div></div>
</blockquote></div><br></div>