<div dir="ltr">It's Friday afternoon, so hopefully you're all relaxing. I am still getting the following error in my browser:<div><br></div><div><div>Authorization Required</div><div><br></div><div>This server could not verify that you are authorized to access the document requested. Either you supplied the wrong credentials (e.g., bad password), or your browser doesn't understand how to supply the credentials required.</div><div><br></div><div>Apache/2.2.15 (CentOS) Server at <a href="http://cas.sou.edu">cas.sou.edu</a> Port 443</div></div><div><br></div><div>In the debug logs on the client I see attributes come over. It looks like the same ones are sent twice:</div><div><br></div><div><div>[Fri Jun 12 16:11:50 2015] [debug] mod_auth_cas.c(539): [client 140.211.91.96] CAS Service 'https%3a%2f%<a href="http://2fcas.sou.edu">2fcas.sou.edu</a>%2fsecure', referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1</a></div><div><br></div><div>[Fri Jun 12 16:11:50 2015] [debug] mod_auth_cas.c(1674): [client 140.211.91.96] Validation response: <?xml version="1.0" encoding="UTF-8"?>\n<soap11:Envelope xmlns:soap11="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>"><soap11:Body><saml1p:Response MajorVersion="1" MinorVersion="1" xmlns:saml1p="urn:oasis:names:tc:SAML:1.0:protocol"><saml1p:Status><saml1p:StatusCode Value="saml1p:Success"/></saml1p:Status><saml1:Assertion AssertionID="_d0a6df8c17fc994bded713a9e7f3740f" IssueInstant="2015-06-12T23:11:50.967Z" Issuer="<a href="https://shib.sou.edu/idp/shibboleth">https://shib.sou.edu/idp/shibboleth</a>" MajorVersion="1" MinorVersion="1" xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"><saml1:Conditions NotBefore="2015-06-12T23:11:50.967Z" NotOnOrAfter="2015-06-12T23:12:50.967Z"><saml1:AudienceRestrictionCondition><saml1:Audience><a href="https://cas.sou.edu/secure">https://cas.sou.edu/secure</a></saml1:Audience></saml1:AudienceRestrictionCondition></saml1:Conditions><saml1:AuthenticationStatement AuthenticationInstant="2015-06-12T23:11:50.967Z" AuthenticationMethod="authn/Password"><saml1:Subject><saml1:NameIdentifier>martinicj</saml1:NameIdentifier><saml1:SubjectConfirmation><saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:artifact</saml1:ConfirmationMethod></saml1:SubjectConfirmation></saml1:Subject></saml1:AuthenticationStatement><saml1:AttributeStatement><saml1:Subject><saml1:NameIdentifier>martinicj</saml1:NameIdentifier><saml1:SubjectConfirmation><saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:artifact</saml1:ConfirmationMethod></saml1:SubjectConfirmation></saml1:Subject><saml1:Attribute AttributeName="eduPersonPrimaryAffiliation" AttributeNamespace="<a href="http://www.ja-sig.org/products/cas/">http://www.ja-sig.org/products/cas/</a>"><saml1:AttributeValue xmlns:xsd="<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>" xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xsd:string">staff</saml1:AttributeValue></saml1:Attribute><saml1:Attribute AttributeName="transientId" AttributeNamespace="<a href="http://www.ja-sig.org/products/cas/">http://www.ja-sig.org/products/cas/</a>"><saml1:AttributeValue xmlns:xsd="<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>" xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xsd:string">_b8e240b3acbc0c93f620214de705e4d7</saml1:AttributeValue></saml1:Attribute><saml1:Attribute AttributeName="mail" AttributeNamespace="<a href="http://www.ja-sig.org/products/cas/">http://www.ja-sig.org/products/cas/</a>"><saml1:AttributeValue xmlns:xsd="<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>" xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xsd:string"><a href="mailto:martinicj@sou.edu">martinicj@sou.edu</a></saml1:AttributeValue></saml1:Attribute><saml1:Attribute AttributeName="eduPersonPrincipalName" AttributeNamespace="<a href="http://www.ja-sig.org/products/cas/">http://www.ja-sig.org/products/cas/</a>"><saml1:AttributeValue xmlns:xsd="<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>" xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xsd:string">martinicj</saml1:AttributeValue></saml1:Attribute></saml1:AttributeStatement></saml1:Assertion></saml1p:Response></soap11:Body></soap11:Envelope>, referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1</a></div><div><br></div><div>[Fri Jun 12 16:11:50 2015] [debug] mod_auth_cas.c(1293): [client 140.211.91.96] entering isValidCASTicket(), referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1</a></div><div><br></div><div>[Fri Jun 12 16:11:50 2015] [debug] mod_auth_cas.c(1299): [client 140.211.91.96] MOD_AUTH_CAS: response = <?xml version="1.0" encoding="UTF-8"?>\n<soap11:Envelope xmlns:soap11="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>"><soap11:Body><saml1p:Response MajorVersion="1" MinorVersion="1" xmlns:saml1p="urn:oasis:names:tc:SAML:1.0:protocol"><saml1p:Status><saml1p:StatusCode Value="saml1p:Success"/></saml1p:Status><saml1:Assertion AssertionID="_d0a6df8c17fc994bded713a9e7f3740f" IssueInstant="2015-06-12T23:11:50.967Z" Issuer="<a href="https://shib.sou.edu/idp/shibboleth">https://shib.sou.edu/idp/shibboleth</a>" MajorVersion="1" MinorVersion="1" xmlns:saml1="urn:oasis:names:tc:SAML:1.0:assertion"><saml1:Conditions NotBefore="2015-06-12T23:11:50.967Z" NotOnOrAfter="2015-06-12T23:12:50.967Z"><saml1:AudienceRestrictionCondition><saml1:Audience><a href="https://cas.sou.edu/secure">https://cas.sou.edu/secure</a></saml1:Audience></saml1:AudienceRestrictionCondition></saml1:Conditions><saml1:AuthenticationStatement AuthenticationInstant="2015-06-12T23:11:50.967Z" AuthenticationMethod="authn/Password"><saml1:Subject><saml1:NameIdentifier>martinicj</saml1:NameIdentifier><saml1:SubjectConfirmation><saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:artifact</saml1:ConfirmationMethod></saml1:SubjectConfirmation></saml1:Subject></saml1:AuthenticationStatement><saml1:AttributeStatement><saml1:Subject><saml1:NameIdentifier>martinicj</saml1:NameIdentifier><saml1:SubjectConfirmation><saml1:ConfirmationMethod>urn:oasis:names:tc:SAML:1.0:cm:artifact</saml1:ConfirmationMethod></saml1:SubjectConfirmation></saml1:Subject><saml1:Attribute AttributeName="eduPersonPrimaryAffiliation" AttributeNamespace="<a href="http://www.ja-sig.org/products/cas/">http://www.ja-sig.org/products/cas/</a>"><saml1:AttributeValue xmlns:xsd="<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>" xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xsd:string">staff</saml1:AttributeValue></saml1:Attribute><saml1:Attribute AttributeName="transientId" AttributeNamespace="<a href="http://www.ja-sig.org/products/cas/">http://www.ja-sig.org/products/cas/</a>"><saml1:AttributeValue xmlns:xsd="<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>" xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xsd:string">_b8e240b3acbc0c93f620214de705e4d7</saml1:AttributeValue></saml1:Attribute><saml1:Attribute AttributeName="mail" AttributeNamespace="<a href="http://www.ja-sig.org/products/cas/">http://www.ja-sig.org/products/cas/</a>"><saml1:AttributeValue xmlns:xsd="<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>" xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xsd:string"><a href="mailto:martinicj@sou.edu">martinicj@sou.edu</a></saml1:AttributeValue></saml1:Attribute><saml1:Attribute AttributeName="eduPersonPrincipalName" AttributeNamespace="<a href="http://www.ja-sig.org/products/cas/">http://www.ja-sig.org/products/cas/</a>"><saml1:AttributeValue xmlns:xsd="<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>" xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xsd:string">martinicj</saml1:AttributeValue></saml1:Attribute></saml1:AttributeStatement></saml1:Assertion></saml1p:Response></soap11:Body></soap11:Envelope>, referer: <a href="https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1">https://shib.sou.edu/idp/profile/cas/login;jsessionid=2F23DBBD54E97013A128DEC6CD8236FC?execution=e1s1</a></div></div><div><br></div><div><br></div><div>I'm stumped. I don't know if my server is still doing something wrong, or if it's just a client-side issue at this point.</div><div><br></div><div>Thanks, and have a good weekend all.</div><div><br></div><div>Jesse</div><div><br></div><div><br></div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><span style="font-size:12.8000001907349px"><b><br></b></span></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><span style="font-size:12.8000001907349px"><b>Jesse Martinich</b></span></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)">Systems Administrator</div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1">Southern Oregon University</font><span style="font-size:12.8000001907349px"> </span><font size="1">| 1250 Siskiyou Blvd </font><font size="1">| Ashland OR  97520</font><br></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1">541-552-8424</font></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><br></font></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><img src="https://docs.google.com/uc?export=download&id=0BwKjt2yacqt7UkNnWGxXaS1VUzQ&revid=0BwKjt2yacqt7bm9QbWZ5ejBHUWdZeGhGZ0VGWFVLTHFHb21BPQ"></font></div></div></div></div></div></div></div></div></div></div></div>
<br><div class="gmail_quote">On Fri, Jun 12, 2015 at 10:46 AM, Jesse Martinich <span dir="ltr"><<a href="mailto:martinicj@sou.edu" target="_blank">martinicj@sou.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Thank you. You saved me from going down that rabbit hole.<div><div></div><div><br></div><div>After enabling the MemcachedStorageService, I now have attributes flowing to the CAS client.</div><div><br></div><div>I am still getting "Authorization Required", but I am guessing that is a client-side configuration issue. I will update after I have dug in some more. </div><div><br></div><div><div>Thanks All!</div><span class="HOEnZb"><font color="#888888"><div><br></div><div>Jesse</div></font></span></div></div></div><div class="gmail_extra"><span class=""><br clear="all"><div><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><span style="font-size:12.8000001907349px"><b><br></b></span></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><span style="font-size:12.8000001907349px"><b>Jesse Martinich</b></span></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)">Systems Administrator</div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1">Southern Oregon University</font><span style="font-size:12.8000001907349px"> </span><font size="1">| 1250 Siskiyou Blvd </font><font size="1">| Ashland OR  97520</font><br></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><a href="tel:541-552-8424" value="+15415528424" target="_blank">541-552-8424</a></font></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><br></font></div><div style="font-size:12.8000001907349px;color:rgb(136,136,136)"><font size="1"><img src="https://docs.google.com/uc?export=download&id=0BwKjt2yacqt7UkNnWGxXaS1VUzQ&revid=0BwKjt2yacqt7bm9QbWZ5ejBHUWdZeGhGZ0VGWFVLTHFHb21BPQ"></font></div></div></div></div></div></div></div></div></div></div></div>
<br></span><div><div class="h5"><div class="gmail_quote">On Fri, Jun 12, 2015 at 10:04 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span>On 6/12/15, 12:47 PM, "users on behalf of Jesse Martinich" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:martinicj@sou.edu" target="_blank">martinicj@sou.edu</a>> wrote:<br>
<br>
>Please excuse my ignorance. I think Walter may have alluded to this yesterday... Might I need to setup back channel support for SOAP endpoints?<br>
<br>
</span>Not if your validation call is using 443.<br>
<br>
In SAML terms, using endpoints protected by commercial certificates and having to implement trust on that basis is a mess. I would imagine that's less true of a CAS scenario where the number of such trusts is one. But I also think there's no reason you couldn't use a back channel port with a self-signed cert either, but you likely wouldn't bother unless you were also doing it for SAML.<br>
<br>
The IdP doesn't really pay attention to the port when it comes to the profile endpoints it runs, so anything on 443 is basically available on 8443 if it's configured to support that.<br>
<span><font color="#888888"><br>
-- Scott<br>
</font></span><div><div><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div></div></div>
</blockquote></div><br></div>