<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">Dear Scott,<div class=""><br class=""></div><div class="">So I ran in DEBUG for a while on the live server, this is the tail end of the debug messages from a login from myself that hung with no response:</div><div class=""><br class=""></div><div class=""><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,372 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.WriteProfileInterceptorResultToStorage:68] - Profile Action WriteProfileInterceptorResultToStorage: No results available from interceptor context, nothing to store</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,373 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.FilterFlowsByNonBrowserSupport:52] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,374 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:65] - Profile Action SelectProfileInterceptorFlow: Moving completed flow intercept/security-policy/saml2-sso to completed set, selecting next one</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,374 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:80] - Profile Action SelectProfileInterceptorFlow: No flows available to choose from</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,375 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeOutboundMessageContext:149] - Profile Action InitializeOutboundMessageContext: Initialized outbound message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,377 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:367] - Profile Action PopulateBindingAndEndpointContexts: Attempting to resolve endpoint of type {urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService for out</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">bound message</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,377 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:505] - Profile Action PopulateBindingAndEndpointContexts: Populating template endpoint for resolution from SAML AuthnRequest</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,378 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:409] - Profile Action PopulateBindingAndEndpointContexts: Resolved endpoint at location <a href="https://www.structuralbiology.eu/Shibboleth.sso/SAML2/POST" class="">https://www.structuralbiology.eu/Shibboleth.sso/SAML2/POST</a> using binding urn:oa</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">sis:names:tc:SAML:2.0:bindings:HTTP-POST</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,382 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:304] - Profile Action PopulateEncryptionParameters: Encryption for assertions (true), identifiers (false), attributes(false)</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,382 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:314] - Profile Action PopulateEncryptionParameters: Resolving EncryptionParameters for request</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,383 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:376] - Profile Action PopulateEncryptionParameters: Adding entityID to resolution criteria</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,383 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:387] - Profile Action PopulateEncryptionParameters: Adding role metadata to resolution criteria</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,384 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:330] - Profile Action PopulateEncryptionParameters: Resolved EncryptionParameters</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,391 - DEBUG [net.shibboleth.idp.saml.profile.impl.ExtractSubjectFromRequest:144] - Profile Action ExtractSubjectFromRequest: No Subject NameID or NameIdentifier in message</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,393 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeAuthenticationContext:101] - Profile Action InitializeAuthenticationContext: Created authentication context AuthenticationContext{initiationInstant=2015-09-16T09:23:18.393+01:00, isPassive=false, forceAuthn=false, hintedName=null, potentialFlows=[], activeResults=[], attemptedFlow=null, signaledFlowId=null, resultCacheable=true, completionInstant=1970-01-01T01:00:00.000+01:00}</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,394 - DEBUG [net.shibboleth.idp.authn.impl.InitializeRequestedPrincipalContext:111] - Profile Action InitializeRequestedPrincipalContext: Profile configuration does not include any default authentication methods</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,395 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.ProcessRequestedAuthnContext:114] - Profile Action ProcessRequestedAuthnContext: AuthnRequest did not contain a RequestedAuthnContext, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,397 - DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:125] - Profile Action PopulateAuthenticationContext: Installing custom PrincipalEvalPredicateFactoryRegistry into AuthenticationContext</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,398 - DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:158] - Profile Action PopulateAuthenticationContext: Installed 1 authentication flows into AuthenticationContext</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,399 - DEBUG [net.shibboleth.idp.session.impl.StorageBackedSessionManager:675] - Performing primary lookup on session ID 93747d3da55494aab0ff8d55cfeee6c56b32d8be52c419c747f27badb4b714b0</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,400 - INFO [net.shibboleth.utilities.java.support.security.DataSealer:216] - Unwrapped data has expired</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,401 - DEBUG [net.shibboleth.idp.session.impl.StorageBackedSessionManager:683] - Primary lookup failed for session ID 93747d3da55494aab0ff8d55cfeee6c56b32d8be52c419c747f27badb4b714b0</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,402 - DEBUG [net.shibboleth.idp.session.impl.PopulateSessionContext:131] - Profile Action PopulateSessionContext: No session found for client</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,403 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByForcedAuthn:53] - Profile Action FilterFlowsByForcedAuthn: Request does not have forced authentication requirement, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,404 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByPassivity:53] - Profile Action FilterFlowsByPassivity: Request does not have passive requirement, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,405 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:53] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,406 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:241] - Profile Action SelectAuthenticationFlow: No specific Principals requested</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,407 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:267] - Profile Action SelectAuthenticationFlow: No usable active results available, selecting an inactive flow</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,407 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:309] - Profile Action SelectAuthenticationFlow: Selecting inactive authentication flow authn/Password</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,409 - DEBUG [net.shibboleth.idp.authn.impl.ExtractUsernamePasswordFromBasicAuth:115] - Profile Action ExtractUsernamePasswordFromBasicAuth: No appropriate Authorization header found</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-16 09:23:18,428 - DEBUG [net.shibboleth.idp.ui.context.RelyingPartyUIContext:360] - Found matching scheme, returning name of '<a href="http://www.structuralbiology.eu" class="">www.structuralbiology.eu</a>'</div></div><div class=""><br class=""><div class="">I can't see anything with my untrained eye as to what might be going wrong, possibly you may have more insight? Thanks for your help here!</div><div class=""><br class=""></div><div class="">Regards,</div><div class=""><br class="webkit-block-placeholder"></div><div apple-content-edited="true" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div class="">Callum Smith</div><div class="">Instruct & Strubi Web Developer</div><div class="">University of Oxford</div><div class="">e. <a href="mailto:callum@strubi.ox.ac.uk" class="">callum@strubi.ox.ac.uk</a></div><div class="">p. +44 (0)1865 2 87782</div></div>
</div>
<br class=""><div><blockquote type="cite" class=""><div class="">On 15 Sep 2015, at 14:41, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" class="">cantor.2@osu.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class="">On 9/15/15, 7:11 AM, "users on behalf of Callum Smith" <<a href="mailto:users-bounces@shibboleth.net" class="">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:callum@strubi.ox.ac.uk" class="">callum@strubi.ox.ac.uk</a>> wrote:<br class=""><br class=""><blockquote type="cite" class="">Running latest IdP v3.1.2 on Tomcat 8.<br class="">Service sits behind reverse proxy over ajp<br class="">OpenJDK 1.7.0_85 on CentOS 5.11<br class="">No errors in the logs.<br class=""></blockquote><br class="">I don't know how to diagnose it if there's no error. The container's not logging anything?<br class=""><br class=""><blockquote type="cite" class="">The server does run memcached with a paired node, both nodes have the IdP setup and running, with the second server set up as a hot swap by the front-end reverse proxy. This feels like the potential cause of issues, should I be looking to change the shibboleth storage engine to something on the disk?<br class=""></blockquote><br class="">Don't have any familiarity with memcache. My advice is always to use client side sessions, not server-side state. Unless you absolutely have to have it, there's no advantage to it.<br class=""><br class="">Since nobody has reported anything like that with the default configuration, I would tend to assume it's storage related.<br class=""><br class="">-- Scott<br class=""><br class="">-- <br class="">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">users-unsubscribe@shibboleth.net</a><br class=""></div></blockquote></div><br class=""></div></body></html>