<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif;"><div>Here’s the trace info when I go to <a href="http://docs.google.com/a/jseppa.com">http://docs.google.com/a/jseppa.com</a></div><span id="OLK_SRC_BODY_SECTION"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0);"><div style="font-size: 14px; font-family: Calibri, sans-serif;"><br></div><div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,821 - DEBUG [org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:64] - Decoded RelayState: <a href="https://www.google.com/a/jseppa.com/ServiceLogin?service=writely&passive=true&continue=https%3A%2F%2Fdocs.google.com%2Fa%2Fjseppa.com%2F%23&followup=https%3A%2F%2Fdocs.google.com%2Fa%2Fjseppa.com%2F<mpl=homepage">https://www.google.com/a/jseppa.com/ServiceLogin?service=writely&passive=true&continue=https%3A%2F%2Fdocs.google.com%2Fa%2Fjseppa.com%2F%23&followup=https%3A%2F%2Fdocs.google.com%2Fa%2Fjseppa.com%2F<mpl=homepage</a></font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,822 - DEBUG [org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:96] - Base64 decoding and inflating SAML message</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,823 - DEBUG [org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:79] - Decoded SAML message</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,823 - DEBUG [PROTOCOL_MESSAGE:121] -</font></span></div><div><span style="font-size: 12px;"><font face="Consolas"><?xml version="1.0" encoding="UTF-8"?></font></span></div><div><span style="font-size: 12px;"><font face="Consolas"><samlp:AuthnRequest</font></span></div><div><span style="font-size: 12px;"><font face="Consolas"> AssertionConsumerServiceURL="<a href="https://www.google.com/a/jseppa.com/acs">https://www.google.com/a/jseppa.com/acs</a>"</font></span></div><div><span style="font-size: 12px;"><font face="Consolas"> ID="gohjohbmlndfeimaibecjgbdemkfpidkfhneafad" IsPassive="false"</font></span></div><div><span style="font-size: 12px;"><font face="Consolas"> IssueInstant="2015-08-01T21:09:06Z"</font></span></div><div><span style="font-size: 12px;"><font face="Consolas"> ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"</font></span></div><div><span style="font-size: 12px;"><font face="Consolas"> ProviderName="google.com" Version="2.0" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"></font></span></div><div><span style="font-size: 12px;"><font face="Consolas"> <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">google.com/a/jseppa.com</saml:Issuer></font></span></div><div><span style="font-size: 12px;"><font face="Consolas"> <samlp:NameIDPolicy AllowCreate="true" Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"/></font></span></div><div><span style="font-size: 12px;"><font face="Consolas"></samlp:AuthnRequest></font></span></div><div><span style="font-size: 12px;"><font face="Consolas"><br></font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,824 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:198] - Profile Action PopulateAuditContext: Skipping field 'p' not included in audit format</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,824 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:198] - Profile Action PopulateAuditContext: Skipping field 'pasv' not included in audit format</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,824 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:220] - Profile Action PopulateAuditContext: Adding 1 value for field 'I'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,824 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:220] - Profile Action PopulateAuditContext: Adding 1 value for field 'b'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,824 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:198] - Profile Action PopulateAuditContext: Skipping field 'D' not included in audit format</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,824 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:198] - Profile Action PopulateAuditContext: Skipping field 'fauth' not included in audit format</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,825 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.CheckMessageVersionHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,825 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,826 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.saml1.binding.impl.SAML1ArtifactRequestIssuerHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,826 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,826 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLProtocolAndRoleHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,826 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,827 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,827 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,828 - DEBUG [org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler:124] - Message Handler: org.opensaml.saml.common.messaging.context.SAMLMetadataContext added to MessageContext</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,830 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLAddAttributeConsumingServiceHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,831 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,831 - DEBUG [org.opensaml.saml.common.binding.impl.SAMLAddAttributeConsumingServiceHandler:129] - Message Handler: Selecting default AttributeConsumingService, if any</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,832 - DEBUG [org.opensaml.saml.metadata.support.AttributeConsumingServiceSelector:186] - Resolving AttributeConsumingService candidates from SPSSODescriptor</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,832 - DEBUG [org.opensaml.saml.metadata.support.AttributeConsumingServiceSelector:141] - AttributeConsumingService candidate list was empty, can not select service</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,832 - DEBUG [org.opensaml.saml.common.binding.impl.SAMLAddAttributeConsumingServiceHandler:137] - Message Handler: No AttributeConsumingService selected</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,833 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeRelyingPartyContextFromSAMLPeer:132] - Profile Action InitializeRelyingPartyContextFromSAMLPeer: Attaching RelyingPartyContext based on SAML peer google.com/a/jseppa.com</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,833 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:284] - Resolving relying party configuration</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,834 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:296] - Checking if relying party configuration EntityNames[google.com/a/jseppa.com,] is applicable</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,834 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:298] - Relying party configuration EntityNames[google.com/a/jseppa.com,] is applicable</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,834 - DEBUG [net.shibboleth.idp.profile.impl.SelectRelyingPartyConfiguration:136] - Profile Action SelectRelyingPartyConfiguration: Found relying party configuration EntityNames[google.com/a/jseppa.com,] for request</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,835 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:220] - Profile Action PopulateAuditContext: Adding 1 value for field 'IDP'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,835 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:220] - Profile Action PopulateAuditContext: Adding 1 value for field 'SP'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,840 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.PopulateProfileInterceptorContext:126] - Profile Action PopulateProfileInterceptorContext: Installing flow intercept/security-policy/saml2-sso into interceptor context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,841 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.FilterFlowsByNonBrowserSupport:52] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,841 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:101] - Profile Action SelectProfileInterceptorFlow: Checking flow intercept/security-policy/saml2-sso for applicability...</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,841 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:84] - Profile Action SelectProfileInterceptorFlow: Selecting flow intercept/security-policy/saml2-sso</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,842 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,842 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,843 - DEBUG [org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:156] - Message Handler: Checking SAML message intended destination endpoint against receiver endpoint</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,843 - DEBUG [org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:175] - Message Handler: SAML message intended destination endpoint was empty, not required by binding, skipping</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,844 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.security.impl.MessageReplaySecurityHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,844 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,844 - DEBUG [org.opensaml.saml.common.binding.security.impl.MessageReplaySecurityHandler:151] - Message Handler: Evaluating message replay for message ID 'gohjohbmlndfeimaibecjgbdemkfpidkfhneafad', issue instant '2015-08-01T21:09:06.000Z', entityID 'google.com/a/jseppa.com'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,845 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.security.impl.MessageLifetimeSecurityHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,845 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,846 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.saml2.binding.security.impl.SAML2AuthnRequestsSignedSecurityHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,846 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,846 - DEBUG [org.opensaml.saml.saml2.binding.security.impl.SAML2AuthnRequestsSignedSecurityHandler:80] - SPSSODescriptor for entity ID 'google.com/a/jseppa.com' does not require AuthnRequests to be signed</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,846 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.security.impl.SAMLProtocolMessageXMLSignatureSecurityHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,847 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,847 - DEBUG [org.opensaml.saml.common.binding.security.impl.SAMLProtocolMessageXMLSignatureSecurityHandler:102] - Message Handler: SAML protocol message was not signed, skipping XML signature processing</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,852 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPRedirectDeflateSignatureSecurityHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,852 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,853 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:148] - Message Handler: Evaluating simple signature rule of type: org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPRedirectDeflateSignatureSecurityHandler</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,853 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:157] - Message Handler: HTTP request was not signed via simple signature mechanism, skipping</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,854 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPPostSimpleSignSecurityHandler' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,854 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,854 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:148] - Message Handler: Evaluating simple signature rule of type: org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPPostSimpleSignSecurityHandler</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,854 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:151] - Message Handler: Handler can not handle this request, skipping processing</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,855 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.messaging.handler.impl.CheckMandatoryIssuer' on INBOUND message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,855 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,856 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.WriteProfileInterceptorResultToStorage:68] - Profile Action WriteProfileInterceptorResultToStorage: No results available from interceptor context, nothing to store</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,856 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.FilterFlowsByNonBrowserSupport:52] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,856 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:65] - Profile Action SelectProfileInterceptorFlow: Moving completed flow intercept/security-policy/saml2-sso to completed set, selecting next one</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,857 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:80] - Profile Action SelectProfileInterceptorFlow: No flows available to choose from</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,860 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeOutboundMessageContext:149] - Profile Action InitializeOutboundMessageContext: Initialized outbound message context</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,862 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:367] - Profile Action PopulateBindingAndEndpointContexts: Attempting to resolve endpoint of type {urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService for outbound message</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,862 - TRACE [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:382] - Profile Action PopulateBindingAndEndpointContexts: Candidate outbound bindings: [urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST, urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign, urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact]</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,862 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:505] - Profile Action PopulateBindingAndEndpointContexts: Populating template endpoint for resolution from SAML AuthnRequest</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,863 - DEBUG [org.opensaml.saml.common.binding.AbstractEndpointResolver:220] - Endpoint Resolver org.opensaml.saml.common.binding.impl.DefaultEndpointResolver: Returning 1 candidate endpoints of type {urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,863 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:409] - Profile Action PopulateBindingAndEndpointContexts: Resolved endpoint at location <a href="https://www.google.com/a/jseppa.com/acs">https://www.google.com/a/jseppa.com/acs</a> using binding urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,869 - DEBUG [org.opensaml.saml.common.profile.impl.PopulateSignatureSigningParameters:184] - Profile Action PopulateSignatureSigningParameters: Signing enabled</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,869 - DEBUG [org.opensaml.saml.common.profile.impl.PopulateSignatureSigningParameters:197] - Profile Action PopulateSignatureSigningParameters: Resolving SignatureSigningParameters for request</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,870 - DEBUG [org.opensaml.saml.common.profile.impl.PopulateSignatureSigningParameters:229] - Profile Action PopulateSignatureSigningParameters: Adding metadata to resolution criteria for signing/digest algorithms</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,870 - DEBUG [org.opensaml.saml.common.profile.impl.PopulateSignatureSigningParameters:237] - Profile Action PopulateSignatureSigningParameters: Resolved SignatureSigningParameters</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,871 - DEBUG [org.opensaml.saml.common.profile.impl.PopulateSignatureSigningParameters:187] - Profile Action PopulateSignatureSigningParameters: Signing not enabled</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,872 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:298] - Profile Action PopulateEncryptionParameters: No encryption requested, nothing to do</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,875 - DEBUG [net.shibboleth.idp.saml.profile.impl.ExtractSubjectFromRequest:144] - Profile Action ExtractSubjectFromRequest: No Subject NameID or NameIdentifier in message</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,875 - DEBUG [org.opensaml.saml.common.profile.impl.VerifyChannelBindings:154] - Profile Action VerifyChannelBindings: No channel bindings found to verify, nothing to do</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,877 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeAuthenticationContext:101] - Profile Action InitializeAuthenticationContext: Created authentication context AuthenticationContext{initiationInstant=2015-08-01T14:09:06.877-07:00, isPassive=false, forceAuthn=false, hintedName=null, potentialFlows=[], activeResults=[], attemptedFlow=null, signaledFlowId=null, resultCacheable=true, completionInstant=1969-12-31T16:00:00.000-08:00}</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,878 - DEBUG [net.shibboleth.idp.session.impl.PopulateSessionContext:131] - Profile Action PopulateSessionContext: No session found for client</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,879 - DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:125] - Profile Action PopulateAuthenticationContext: Installing custom PrincipalEvalPredicateFactoryRegistry into AuthenticationContext</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,879 - DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:158] - Profile Action PopulateAuthenticationContext: Installed 1 authentication flows into AuthenticationContext</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,879 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByForcedAuthn:53] - Profile Action FilterFlowsByForcedAuthn: Request does not have forced authentication requirement, nothing to do</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,880 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByPassivity:53] - Profile Action FilterFlowsByPassivity: Request does not have passive requirement, nothing to do</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,880 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:53] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,881 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:241] - Profile Action SelectAuthenticationFlow: No specific Principals requested</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,881 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:267] - Profile Action SelectAuthenticationFlow: No usable active results available, selecting an inactive flow</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,881 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:309] - Profile Action SelectAuthenticationFlow: Selecting inactive authentication flow authn/Password</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,882 - DEBUG [net.shibboleth.idp.authn.impl.ExtractUsernamePasswordFromBasicAuth:115] - Profile Action ExtractUsernamePasswordFromBasicAuth: No appropriate Authorization header found</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,912 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:315] - No name in UIINFO for 'en'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,913 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:315] - No name in UIINFO for 'en'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,913 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:315] - No name in UIINFO for 'en'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,913 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:315] - No name in UIINFO for 'fr'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,914 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:315] - No name in UIINFO for 'de'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,914 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:363] - Not a usual scheme, returning name of 'google.com/a/jseppa.com'</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,917 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:787] - No UIInfo or logos returning null</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,917 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:380] - No UIInfo</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,918 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:402] - No ACS found</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,918 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:380] - No UIInfo</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,918 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:402] - No ACS found</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,919 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:380] - No UIInfo</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,919 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:402] - No ACS found</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,919 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:380] - No UIInfo</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,919 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:402] - No ACS found</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,919 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:380] - No UIInfo</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,919 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:402] - No ACS found</font></span></div><div><span style="font-size: 12px;"><font face="Consolas">2015-08-01 14:09:06,920 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:529] - No description matching the languages found, returning null</font></span></div></div><div style="font-size: 14px; font-family: Calibri, sans-serif;"><br></div><div style="font-size: 14px; font-family: Calibri, sans-serif;"><br></div><div style="font-size: 14px; font-family: Calibri, sans-serif;"><br></div><div style="font-size: 14px; font-family: Calibri, sans-serif;"><br></div><div style="font-size: 14px; font-family: Calibri, sans-serif;">And then type username/password at idp login form yields:</div><div style="font-size: 14px; font-family: Calibri, sans-serif;"><br></div><div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,056 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:315] - No name in UIINFO for 'en'</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,057 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:315] - No name in UIINFO for 'en'</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,057 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:315] - No name in UIINFO for 'en'</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,058 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:315] - No name in UIINFO for 'fr'</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,058 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:315] - No name in UIINFO for 'de'</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,058 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:363] - Not a usual scheme, returning name of 'google.com/a/jseppa.com'</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,059 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:787] - No UIInfo or logos returning null</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,059 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:380] - No UIInfo</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,059 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:402] - No ACS found</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,059 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:380] - No UIInfo</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,059 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:402] - No ACS found</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,060 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:380] - No UIInfo</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,060 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:402] - No ACS found</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,060 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:380] - No UIInfo</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,060 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:402] - No ACS found</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,060 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:380] - No UIInfo</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,060 - TRACE [net.shibboleth.idp.ui.context.RelyingPartyUIContext:402] - No ACS found</font></div><div><font face="Courier" style="font-size: 12px;">2015-08-01 14:05:21,061 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:529] - No description matching the languages found, returning null</font></div></div><div style="font-size: 14px; font-family: Calibri, sans-serif;"><br></div><div style="font-size: 14px; font-family: Calibri, sans-serif;"><br></div><div style="font-size: 14px; font-family: Calibri, sans-serif;"><br></div><div style="font-size: 14px; font-family: Calibri, sans-serif;"><br></div><span id="OLK_SRC_BODY_SECTION" style="font-size: 14px; font-family: Calibri, sans-serif;"><div style="font-family:Calibri; font-size:11pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt"><span style="font-family: Consolas; font-size: 14px;">Date: Sat, 1 Aug 2015 07:57:54 -0500</span></div><div><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif;"><div style="font-family: Consolas;">From: Tom Zeller <<a href="mailto:tzeller@dragonacea.biz">tzeller@dragonacea.biz</a>></div><div style="font-family: Consolas;">To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>></div><div style="font-family: Consolas;">Subject: Re: idp login issue connecting to ldap</div><div style="font-family: Consolas;">Message-ID: <<a href="mailto:B5D24CD0-EC4A-4BD5-88C2-13E287CEE9F8@dragonacea.biz">B5D24CD0-EC4A-4BD5-88C2-13E287CEE9F8@dragonacea.biz</a>></div><div style="font-family: Consolas;">Content-Type: text/plain; charset="us-ascii"</div><div style="font-family: Consolas;"><br></div><div style="font-family: Consolas;"><br></div><div style="font-family: Consolas;"><br></div><blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="font-family: Consolas; border-left-color: rgb(181, 196, 223); border-left-width: 5px; border-left-style: solid; padding: 0px 0px 0px 5px; margin: 0px 0px 0px 5px;"><div>On Jul 31, 2015, at 11:33 PM, Jason Separovic <<a href="mailto:jseppa01@gmail.com">jseppa01@gmail.com</a>> wrote:</div><div></div><div>Hi,</div><div></div><div>I'm trying to setup a simple google apps test case with idp 3.1.2. I also have openldap 2.4.39-8.el6 setup on the same host</div><div></div><div>It seems as though ldap is working fine when I use the aacli command:</div><div></div><div>[root@dev1 bin]# ./aacli.sh --requester google.com --principal jason</div><div></div><div>{</div><div>"requester": "google.com",</div><div>"principal": "jason",</div><div>"attributes": [</div><div></div><div></div><div> {</div><div> "name": "googleNameID",</div><div> "values": [</div><div> "StringAttributeValue{<a href="mailto:value=jason@jseppa.com">value=jason@jseppa.com</a>}" ]</div><div> } </div><div></div><div>]</div><div>}</div><div></div><div></div><div>However, when I direct my browser to the google api, I get redirected to the idp login page as expected, however when I enter the ldap user/pass, the form just returns another blank form.</div><div>Tcpdump on 389 reveals no attempt to connect to ldap and, org.ldaptive TRACE shows nothing in the logs.</div><div></div><div>I'm using the following ldap in the attribute resolver, so I think the ldap.properties should be good:</div><div></div><div> <resolver:DataConnector id="ldap" xsi:type="dc:LDAPDirectory"</div><div> ldapURL="%{idp.attribute.resolver.LDAP.ldapURL}"</div><div> baseDN="%{idp.attribute.resolver.LDAP.baseDN}" </div><div> principal="%{idp.attribute.resolver.LDAP.bindDN}"</div><div> principalCredential="%{idp.attribute.resolver.LDAP.bindDNCredential}"></div><div> <dc:FilterTemplate></div><div> <![CDATA[</div><div> %{idp.attribute.resolver.LDAP.searchFilter}</div><div> ]]></div><div> </dc:FilterTemplate></div><div> </resolver:DataConnector></div><div></div><div>Is there anything that needs to be configured in order to use ldap in the auth process? I'm sure I'm missing something simple here, just beating my head against the wall a bit.</div></blockquote><div style="font-family: Consolas;"><br></div><div style="font-family: Consolas;">The blank form sounds odd, but without more info I suggest start there.</div></div></div></span></div></span></body></html>