<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">Dear All,<div class=""><br class=""></div><div class="">Thanks again for your contributions. I have finally got a debug log of a "failed" authentication, that is one that times out and requires refreshing. I'm going to attach the whole log for this fail as not to miss out any potentially significant information. Any insight or help would be greatly appreciated.</div><div class=""><br class=""></div><div class=""><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,140 - DEBUG [org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:64] - Decoded RelayState: ss:mem:62890704854e418bd79fb0e5df939a0a1cabd802f695e66ca96dd7011fe2bc72</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,140 - DEBUG [org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:96] - Base64 decoding and inflating SAML message</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,141 - DEBUG [org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:79] - Decoded SAML message</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,142 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:198] - Profile Action PopulateAuditContext: Skipping field 'fauth' not included in audit format</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,142 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:198] - Profile Action PopulateAuditContext: Skipping field 'D' not included in audit format</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,142 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:198] - Profile Action PopulateAuditContext: Skipping field 'pasv' not included in audit format</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,143 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:220] - Profile Action PopulateAuditContext: Adding 1 value for field 'b'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,143 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:220] - Profile Action PopulateAuditContext: Adding 1 value for field 'I'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,143 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:198] - Profile Action PopulateAuditContext: Skipping field 'p' not included in audit format</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,144 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.CheckMessageVersionHandler' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,144 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,145 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.saml1.binding.impl.SAML1ArtifactRequestIssuerHandler' on INBOUND message c</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">ontext</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,145 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,146 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLProtocolAndRoleHandler' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,146 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,147 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,147 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,148 - DEBUG [org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler:124] - Message Handler: org.opensaml.saml.common.messaging.context.SAMLMetadataContext added to MessageContext</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,148 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLAddAttributeConsumingServiceHandler' on INBOUND me</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">ssage context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,149 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,149 - DEBUG [org.opensaml.saml.common.binding.impl.SAMLAddAttributeConsumingServiceHandler:129] - Message Handler: Selecting default AttributeConsumingService, if any</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,149 - DEBUG [org.opensaml.saml.metadata.support.AttributeConsumingServiceSelector:186] - Resolving AttributeConsumingService candidates from SPSSODescriptor</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,149 - DEBUG [org.opensaml.saml.metadata.support.AttributeConsumingServiceSelector:141] - AttributeConsumingService candidate list was empty, can not select service</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,149 - DEBUG [org.opensaml.saml.common.binding.impl.SAMLAddAttributeConsumingServiceHandler:137] - Message Handler: No AttributeConsumingService selected</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,150 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeRelyingPartyContextFromSAMLPeer:132] - Profile Action InitializeRelyingPartyContextFromSAMLPeer: Attaching RelyingPartyContext based on SAML peer <a href="https://www.structuralbiology.eu/shibboleth" class="">https://www.structuralbiology.eu/shibboleth</a></div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,150 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:284] - Resolving relying party configuration</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,150 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:305] - No relying party configurations are applicable, returning the default configuration shibboleth.DefaultRelyingParty</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,151 - DEBUG [net.shibboleth.idp.profile.impl.SelectRelyingPartyConfiguration:136] - Profile Action SelectRelyingPartyConfiguration: Found relying party configuration shibboleth.DefaultRelyingParty for request</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,151 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:220] - Profile Action PopulateAuditContext: Adding 1 value for field 'SP'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,151 - DEBUG [net.shibboleth.idp.profile.audit.impl.PopulateAuditContext:220] - Profile Action PopulateAuditContext: Adding 1 value for field 'IDP'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,153 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.PopulateProfileInterceptorContext:126] - Profile Action PopulateProfileInterceptorContext: Installing flow intercept/security-policy/saml2-sso into interceptor context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,154 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.FilterFlowsByNonBrowserSupport:52] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,154 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:101] - Profile Action SelectProfileInterceptorFlow: Checking flow intercept/security-policy/saml2-sso for applicability...</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,154 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:84] - Profile Action SelectProfileInterceptorFlow: Selecting flow intercept/security-policy/saml2-sso</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,156 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,156 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,156 - DEBUG [org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:156] - Message Handler: Checking SAML message intended destination endpoint against receiver endpoint</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,156 - DEBUG [org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:189] - Message Handler: Intended message destination endpoint: <a href="https://www.structuralbiology.eu/idp/profile/SAML2/Redirect/SSO" class="">https://www.structuralbiology.eu/idp/profile/SAML2/Redirect/SSO</a></div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,157 - DEBUG [org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:190] - Message Handler: Actual message receiver endpoint: <a href="https://www.structuralbiology.eu/idp/profile/SAML2/Redirect/SSO" class="">https://www.structuralbiology.eu/idp/profile/SAML2/Redirect/SSO</a></div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,157 - DEBUG [org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:203] - Message Handler: SAML message intended destination endpoint matched recipient endpoint</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,158 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.security.impl.MessageReplaySecurityHandler' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,158 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,158 - DEBUG [org.opensaml.saml.common.binding.security.impl.MessageReplaySecurityHandler:151] - Message Handler: Evaluating message replay for message ID '_766521bf215d28e299a7b80394d01536', issue instant '2015-09-28T08:52:36.000Z', entityID '<a href="https://www.structuralbiology.eu/shibboleth'" class="">https://www.structuralbiology.eu/shibboleth'</a></div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,159 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.security.impl.MessageLifetimeSecurityHandler' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,160 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,161 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.saml2.binding.security.impl.SAML2AuthnRequestsSignedSecurityHandler' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,161 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,161 - DEBUG [org.opensaml.saml.saml2.binding.security.impl.SAML2AuthnRequestsSignedSecurityHandler:80] - SPSSODescriptor for entity ID '<a href="https://www.structuralbiology.eu/shibboleth'" class="">https://www.structuralbiology.eu/shibboleth'</a> does not require AuthnRequests to be signed</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,162 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.security.impl.SAMLProtocolMessageXMLSignatureSecurityHandler' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,162 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,162 - DEBUG [org.opensaml.saml.common.binding.security.impl.SAMLProtocolMessageXMLSignatureSecurityHandler:102] - Message Handler: SAML protocol message was not signed, skipping XML signature processing</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,163 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPRedirectDeflateSignatureSecurityHandler' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,164 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,164 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:148] - Message Handler: Evaluating simple signature rule of type: org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPRedirectDeflateSignatureSecurityHandler</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,164 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:157] - Message Handler: HTTP request was not signed via simple signature mechanism, skipping</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,165 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPPostSimpleSignSecurityHandler' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,165 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,166 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:148] - Message Handler: Evaluating simple signature rule of type: org.opensaml.saml.saml2.binding.security.impl.SAML2HTTPPostSimpleSignSecurityHandler</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,166 - DEBUG [org.opensaml.saml.common.binding.security.impl.BaseSAMLSimpleSignatureSecurityHandler:151] - Message Handler: Handler can not handle this request, skipping processing</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,167 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.messaging.handler.impl.CheckMandatoryIssuer' on INBOUND message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,167 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,168 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.WriteProfileInterceptorResultToStorage:68] - Profile Action WriteProfileInterceptorResultToStorage: No results available from interceptor context, nothing to store</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,168 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.FilterFlowsByNonBrowserSupport:52] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,169 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:65] - Profile Action SelectProfileInterceptorFlow: Moving completed flow intercept/security-policy/saml2-sso to completed set, selecting next one</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,169 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:80] - Profile Action SelectProfileInterceptorFlow: No flows available to choose from</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,170 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeOutboundMessageContext:149] - Profile Action InitializeOutboundMessageContext: Initialized outbound message context</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,171 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:367] - Profile Action PopulateBindingAndEndpointContexts: Attempting to resolve endpoint of type {urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService for outbound message</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,171 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:505] - Profile Action PopulateBindingAndEndpointContexts: Populating template endpoint for resolution from SAML AuthnRequest</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,171 - DEBUG [org.opensaml.saml.common.binding.AbstractEndpointResolver:220] - Endpoint Resolver org.opensaml.saml.common.binding.impl.DefaultEndpointResolver: Returning 6 candidate endpoints of type {urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService</div></div><div class=""><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,172 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:409] - Profile Action PopulateBindingAndEndpointContexts: Resolved endpoint at location <a href="https://www.structuralbiology.eu/Shibboleth.sso/SAML2/POST" class="">https://www.structuralbiology.eu/Shibboleth.sso/SAML2/POST</a> using binding urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,172 - DEBUG [org.opensaml.saml.common.profile.impl.PopulateSignatureSigningParameters:184] - Profile Action PopulateSignatureSigningParameters: Signing enabled</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,173 - DEBUG [org.opensaml.saml.common.profile.impl.PopulateSignatureSigningParameters:197] - Profile Action PopulateSignatureSigningParameters: Resolving SignatureSigningParameters for request</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,173 - DEBUG [org.opensaml.saml.common.profile.impl.PopulateSignatureSigningParameters:229] - Profile Action PopulateSignatureSigningParameters: Adding metadata to resolution criteria for signing/digest algorithms</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,174 - DEBUG [org.opensaml.saml.security.impl.SAMLMetadataSignatureSigningParametersResolver:108] - Resolved signature algorithm URI from SAML metadata SigningMethod: <a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512" class="">http://www.w3.org/2001/04/xmldsig-more#rsa-sha512</a></div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,174 - DEBUG [org.opensaml.saml.security.impl.SAMLMetadataSignatureSigningParametersResolver:189] - Resolved reference digest method algorithm URI from SAML metadata DigestMethod: <a href="http://www.w3.org/2001/04/xmlenc#sha512" class="">http://www.w3.org/2001/04/xmlenc#sha512</a></div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,174 - DEBUG [org.opensaml.saml.common.profile.impl.PopulateSignatureSigningParameters:237] - Profile Action PopulateSignatureSigningParameters: Resolved SignatureSigningParameters</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,176 - DEBUG [org.opensaml.saml.common.profile.impl.PopulateSignatureSigningParameters:187] - Profile Action PopulateSignatureSigningParameters: Signing not enabled</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,176 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:304] - Profile Action PopulateEncryptionParameters: Encryption for assertions (true), identifiers (false), attributes(false)</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,177 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:314] - Profile Action PopulateEncryptionParameters: Resolving EncryptionParameters for request</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,177 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:376] - Profile Action PopulateEncryptionParameters: Adding entityID to resolution criteria</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,177 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:387] - Profile Action PopulateEncryptionParameters: Adding role metadata to resolution criteria</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,178 - DEBUG [org.opensaml.saml.security.impl.MetadataCredentialResolver:259] - Resolving credentials from supplied RoleDescriptor using usage: ENCRYPTION. Effective entityID was: <a href="https://www.structuralbiology.eu/shibboleth" class="">https://www.structuralbiology.eu/shibboleth</a></div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,178 - DEBUG [org.opensaml.saml.security.impl.MetadataCredentialResolver:350] - Resolved cached credentials from KeyDescriptor object metadata</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,178 - DEBUG [org.opensaml.saml.security.impl.SAMLMetadataEncryptionParametersResolver:381] - Resolved data encryption algorithm URI from SAML metadata EncryptionMethod: <a href="http://www.w3.org/2001/04/xmlenc#aes128-cbc" class="">http://www.w3.org/2001/04/xmlenc#aes128-cbc</a></div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,179 - DEBUG [org.opensaml.saml.security.impl.SAMLMetadataEncryptionParametersResolver:335] - Resolved key transport algorithm URI from SAML metadata EncryptionMethod: <a href="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p" class="">http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p</a></div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,179 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.PopulateEncryptionParameters:330] - Profile Action PopulateEncryptionParameters: Resolved EncryptionParameters</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,184 - DEBUG [net.shibboleth.idp.saml.profile.impl.ExtractSubjectFromRequest:144] - Profile Action ExtractSubjectFromRequest: No Subject NameID or NameIdentifier in message</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,184 - DEBUG [org.opensaml.saml.common.profile.impl.VerifyChannelBindings:154] - Profile Action VerifyChannelBindings: No channel bindings found to verify, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,186 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeAuthenticationContext:101] - Profile Action InitializeAuthenticationContext: Created authentication context AuthenticationContext{initiationInstant=2015-09-28T09:52:36.186+01:00, isPassive=false, forceAuthn=false, hintedName=null, potentialFlows=[], activeResults=[], attemptedFlow=null, signaledFlowId=null, resultCacheable=true, completionInstant=1970-01-01T01:00:00.000+01:00}</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,187 - DEBUG [net.shibboleth.idp.authn.impl.InitializeRequestedPrincipalContext:111] - Profile Action InitializeRequestedPrincipalContext: Profile configuration does not include any default authentication methods</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,187 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.ProcessRequestedAuthnContext:114] - Profile Action ProcessRequestedAuthnContext: AuthnRequest did not contain a RequestedAuthnContext, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,188 - DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:125] - Profile Action PopulateAuthenticationContext: Installing custom PrincipalEvalPredicateFactoryRegistry into AuthenticationContext</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,188 - DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:158] - Profile Action PopulateAuthenticationContext: Installed 1 authentication flows into AuthenticationContext</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,189 - DEBUG [net.shibboleth.idp.session.impl.StorageBackedSessionManager:675] - Performing primary lookup on session ID d3fb74b7d8f9910cc3e6085842d8dd3e0cdaf3ebce1c3d29593170833e036b9b</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,192 - DEBUG [net.shibboleth.idp.session.impl.StorageBackedIdPSession:90] - Updating expiration of master record for session d3fb74b7d8f9910cc3e6085842d8dd3e0cdaf3ebce1c3d29593170833e036b9b to 2015-09-28T10:52:36.191+01:00</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,193 - DEBUG [net.shibboleth.idp.session.impl.StorageBackedIdPSession:523] - Loading AuthenticationResult for flow authn/Password in session d3fb74b7d8f9910cc3e6085842d8dd3e0cdaf3ebce1c3d29593170833e036b9b</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,194 - DEBUG [net.shibboleth.idp.session.impl.ExtractActiveAuthenticationResults:116] - Profile Action ExtractActiveAuthenticationResults: authentication result authn/Password is inactive, skipping it</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,195 - DEBUG [net.shibboleth.idp.session.impl.ExtractActiveAuthenticationResults:122] - Profile Action ExtractActiveAuthenticationResults: no active authentication results, SSO will not be possible</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,197 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByForcedAuthn:53] - Profile Action FilterFlowsByForcedAuthn: Request does not have forced authentication requirement, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,197 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByPassivity:53] - Profile Action FilterFlowsByPassivity: Request does not have passive requirement, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,198 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:53] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,199 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:241] - Profile Action SelectAuthenticationFlow: No specific Principals requested</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,199 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:267] - Profile Action SelectAuthenticationFlow: No usable active results available, selecting an inactive flow</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,199 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:309] - Profile Action SelectAuthenticationFlow: Selecting inactive authentication flow authn/Password</div><div style="margin: 0px; font-size: 11px; font-family: Menlo;" class="">2015-09-28 09:52:36,200 - DEBUG [net.shibboleth.idp.authn.impl.ExtractUsernamePasswordFromBasicAuth:115] - Profile Action ExtractUsernamePasswordFromBasicAuth: No appropriate Authorization header found</div></div><div class=""><br class=""></div><div class="">Regards,</div><div class=""><br class=""></div><div class=""><div apple-content-edited="true" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div class="">Callum Smith</div><div class="">Instruct & Strubi Web Developer</div><div class="">University of Oxford</div><div class="">e. <a href="mailto:callum@strubi.ox.ac.uk" class="">callum@strubi.ox.ac.uk</a></div><div class="">p. +44 (0)1865 2 87782</div></div>
</div>
<br class=""><div><blockquote type="cite" class=""><div class="">On 25 Sep 2015, at 14:44, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" class="">cantor.2@osu.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class="">On 9/25/15, 6:01 AM, "users on behalf of Callum Smith" <<a href="mailto:users-bounces@shibboleth.net" class="">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:callum@strubi.ox.ac.uk" class="">callum@strubi.ox.ac.uk</a>> wrote:<br class=""><br class=""><blockquote type="cite" class="">These are the only errors I can find after a few days of running at DEBUG (the second one occurs a few times, but still in a rare occurrence compared to successful authentications):<br class=""></blockquote><br class="">Those are back button errors. That doesn't impact a new request.<br class=""><br class="">-- Scott<br class=""><br class="">-- <br class="">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">users-unsubscribe@shibboleth.net</a><br class=""></div></blockquote></div><br class=""></div></body></html>