<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Trebuchet MS";
        panose-1:2 11 6 3 2 2 2 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">Ever since we’ve started using the IDP 2.4.4 and MCB 1.2.5 in preparation for rolling out 2factor we have our users seeing the AuthnFailed message when after
 authenticating to one sp previously opens a new browser tab and visits an sp that is set to force re-authentication. One of our other schools with a similar setup disabled their setup for previous sessions to get around this issue. We were wondering if this
 was a known issue for this scenario or are we missing something with our config on the sp or idp possibly? I’ll paste the idp log snippet below<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">Idp log snip.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">14:05:51.971 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:680] - Force reauth = [true]<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">14:05:51.971 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:684] - Found [0] allowable contexts to choose from.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">14:05:51.971 - DEBUG [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:712] - Relying party did not request a context, using potential
 context list for the user.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">14:05:51.971 - WARN [edu.internet2.middleware.assurance.mcb.authn.provider.MCBLoginServlet:732] - Unable to satisfy requested authentication context of [[]].
 Returning SAML error to SP.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">14:05:51.971 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:144] - Returning control to authentication engine<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">14:05:51.971 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:209] - Processing incoming request<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">14:05:51.971 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:514] - Completing user authentication process<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">14:05:51.971 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:585] - Validating authentication was performed successfully<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">14:05:51.971 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:605] - Exception returned from login handler for authentication method
 urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">edu.internet2.middleware.shibboleth.idp.authn.AuthenticationException: Unable to satisfy requested authentication context.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">Login error below.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Trebuchet MS",sans-serif;color:black">SAML response contained an error.<br>
<br>
Error from identity provider:<br>
<br>
Status: urn:oasis:names:tc:SAML:2.0:status:Responder<br>
<br>
Sub-Status: urn:oasis:names:tc:SAML:2.0:status:AuthnFailed</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif">William Ewing, Senior Information Security Analyst<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif">CISSP, MCSE, MCITP-EA, CCNA/CCDA<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif">UT System – Office of Information Security & Compliance<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">210 West 6th Street<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Courier New"">Austin, Texas 78701-3035
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif">Phone: (512)499-4575<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Arial",sans-serif">email:
<a href="mailto:bewing@utsystem.edu"><span style="color:blue">bewing@utsystem.edu</span></a></span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>