<div dir="ltr">Do you have a <Context> defined in your multi-context-broker.xml file for PasswordProtectedTransport?  <div><br></div><div>Dave</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Jun 23, 2015 at 6:45 PM, IAM David Bantz <span dir="ltr"><<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">A vendor (<a href="http://afford.com" target="_blank">afford.com</a>'s TMS) is sending a SAML request my IdP 2.x with MCB cannot handle.<div>Here's the initial sign of trouble in my IdP process log:</div><div><br></div><div>







<p><span>12:37:43.141 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:400] - <br>                        Error decoding authentication request message </span>org.opensaml.ws.message.decoder.MessageDecodingException: <br>                        No SAMLRequest or SAMLResponse query path parameter, invalid SAML 2 HTTP Redirect message</p><p>(Is there a logging setting that will display the exact unencoded SAML request in the process log?)</p>
<p>According to the vendor, the IdP needs to support PasswordProtectedTransport Authentication in relying-party.xml, but as we have MCB installed, I think there's more to it.  Here's what the MCB adds to the logs for this request; although the user's input did authenticate via LDAP directory (and attributes were resolved) this does not satisfy the request:</p><p><span>12:38:40.676 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:227] - <br>                        User authenticated with method [password]</span></p><p><span>12:38:40.676 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:257] - <br>                        Used context listed in valid contexts = [false]</span></p><p><span>12:38:40.676 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:261] - <br>                        User [</span><span>uaguest_bb</span><span>ouchard1] used a context NOT on the potential context list. They must re-authenticate with a valid context.</span></p><p><span>12:38:40.676 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:544] -<br>                        Found [0] allowable contexts to choose from.</span></p><p><span>12:38:40.677 - WARN [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:573] - <br>                        Unable to satisfy requested authentication context of [[urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport]]. Returning SAM</span>L error to SP.</p><p>with the result:</p><p>







</p><p><span>12:38:40.677 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:156] - Authentication result = [false]</span></p><p>What do I need to change to support the vendor's SAML request for PasswordProtectedTransport authentication method?</p><p>David Bantz<br>U Alaska IAM</p></div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr"><div>David Langenberg<div>Identity & Access Management Architect</div><div>The University of Chicago</div></div></div></div>
</div>