<div dir="ltr">Thank you. I'm not sure which cert I should make sure I am trusting. Using s_client just checks the ssl cert being used for Tomcat SSL. Don't I need to make sure idp-signing.crt is being trusted?<div><br></div><div>Thanks,</div><div>Jesse<br><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><span style="font-size:12.8000001907349px"><b><br></b></span></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><span style="font-size:12.8000001907349px"><b>Jesse Martinich</b></span></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)">Systems Administrator</div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1">Southern Oregon University</font><span style="font-size:12.8000001907349px"> </span><font size="1">| 1250 Siskiyou Blvd </font><font size="1">| Ashland OR 97520</font><br></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1">541-552-8424</font></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><br></font></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><img src="https://docs.google.com/uc?export=download&id=0BwKjt2yacqt7UkNnWGxXaS1VUzQ&revid=0BwKjt2yacqt7bm9QbWZ5ejBHUWdZeGhGZ0VGWFVLTHFHb21BPQ"></font></div></div></div></div></div></div></div></div></div></div></div>
<br><div class="gmail_quote">On Thu, Jun 11, 2015 at 2:12 PM, Walter Forbes Hoehn (wassa) <span dir="ltr"><<a href="mailto:wassa@memphis.edu" target="_blank">wassa@memphis.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Verify that your CASCertificatePath parameter is in fact pointing to an appropriate trust root. You can test with openssl s_client pointed at the same file.<br>
<span class="HOEnZb"><font color="#888888"><br>
-WFH<br>
</font></span><span class="im HOEnZb"><br>
<br>
> On Jun 11, 2015, at 3:54 PM, Jesse Martinich <<a href="mailto:martinicj@sou.edu">martinicj@sou.edu</a>> wrote:<br>
><br>
> I'm getting the following in debug:<br>
><br>
> [Thu Jun 11 13:50:52 2015] [info] Initial (No.1) HTTPS request received for child 0 (server <a href="http://cas.sou.edu:443" target="_blank">cas.sou.edu:443</a>)<br>
> [Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(1745): [client 140.211.91.96] Entering cas_authenticate(), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1" target="_blank">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a><br>
> [Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(607): [client 140.211.91.96] Modified r->args (old 'ticket=ST-1434055852427-bjIkFqajBP0IVHqJfUbxUY0GA', new ''), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1" target="_blank">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a><br>
> [Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(1600): [client 140.211.91.96] entering getResponseFromServer(), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1" target="_blank">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a><br>
> [Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(519): [client 140.211.91.96] entering getCASService(), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1" target="_blank">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a><br>
> [Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(539): [client 140.211.91.96] CAS Service 'https%3a%2f%<a href="http://2fcas.sou.edu" target="_blank">2fcas.sou.edu</a>%2fsecure%2f', referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1" target="_blank">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a><br>
> [Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(1666): [client 140.211.91.96] MOD_AUTH_CAS: curl_easy_perform() failed (Peer certificate cannot be authenticated with known CA certificates), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1" target="_blank">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a><br>
> [Thu Jun 11 13:50:52 2015] [debug] mod_auth_cas.c(1293): [client 140.211.91.96] entering isValidCASTicket(), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1" target="_blank">https://shib.sou.edu/idp/profile/cas/login;jsessionid=F12024FBC898014BF3632F8A8FAFDCAE?execution=e1s1</a><br>
> [Thu Jun 11 13:50:52 2015] [debug] ssl_engine_kernel.c(1863): OpenSSL: Write: SSL negotiation finished successfully<br>
> [Thu Jun 11 13:50:52 2015] [info] [client 140.211.91.96] Connection closed to child 0 with standard shutdown (server <a href="http://cas.sou.edu:443" target="_blank">cas.sou.edu:443</a>)<br>
><br>
><br>
><br>
> Jesse Martinich<br>
> Systems Administrator<br>
> Southern Oregon University | 1250 Siskiyou Blvd | Ashland OR 97520<br>
> <a href="tel:541-552-8424" value="+15415528424">541-552-8424</a><br>
><br>
></span><span class="im HOEnZb"><br>
><br>
> On Thu, Jun 11, 2015 at 1:46 PM, Jesse Martinich <<a href="mailto:martinicj@sou.edu">martinicj@sou.edu</a>> wrote:<br>
> I previously overlooked the lack of debug messages. I had not changed the LogLevel in my vhost to debug, so it was still at warn. I am now seeing a cert issue, looks like I am trusting the Web SSL cert but not the IDP cert.<br>
><br>
> Will update after attempting fix.<br>
><br>
> Thanks!<br>
> Jesse<br>
><br>
><br>
> Jesse Martinich<br>
> Systems Administrator<br>
> Southern Oregon University | 1250 Siskiyou Blvd | Ashland OR 97520<br>
> <a href="tel:541-552-8424" value="+15415528424">541-552-8424</a><br>
><br>
></span><div class="HOEnZb"><div class="h5">
><br>
> On Thu, Jun 11, 2015 at 1:35 PM, Walter Forbes Hoehn (wassa) <<a href="mailto:wassa@memphis.edu">wassa@memphis.edu</a>> wrote:<br>
> Ditto what Marvin said below. You are going to have to check the client end. The only additional information I’ll add is that every time I’ve seen this in the past it has been one of two things:<br>
><br>
> 1) The CAS client was rejecting the CAS server SSL certificate<br>
><br>
> 2) The CAS client was very old and was not parsing the SOAP envelope correctly. This was with the CAS client for Java, so it probably doesn’t apply.<br>
><br>
> Firewall issues probably don’t come into play all that often, because most folks are running CAS back-channel requests on port 443 along with the /login endpoint.<br>
><br>
> -Walter<br>
><br>
><br>
> > On Jun 11, 2015, at 3:23 PM, Marvin Addison <<a href="mailto:marvin.addison@gmail.com">marvin.addison@gmail.com</a>> wrote:<br>
> ><br>
> > 140.211.91.96 - - [11/Jun/2015:12:58:30 -0700] "POST /idp/profile/cas/login;jsessionid=85B70E3AD0AEF47512F7D2D787BEBDCC?execution=e1s1 HTTP/1.1" 302 -<br>
> ><br>
> > The request to /idp/profile/cas/samlValidate to validate the ticket ought to follow shortly after the credential submission above. I think we need to focus on mod_auth_cas debug output in the Apache error log. What does it say?<br>
><br>
> --<br>
> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
><br>
><br>
> --<br>
> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></div></blockquote></div><br></div></div></div>