<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hi,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Single-sign on no longer works with the 3.2.1 that I am testing.  It was working a few days ago before I worked on fixing some NameID issues.  It appears to be a session issue and here is the log data after somone logs in:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">2016-03-03 03:37:53,545 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByForcedAuthn:53] - Profile Action FilterFlowsByForcedAuthn: Request does not have forced authentication requirement, nothing to do<o:p></o:p></p>
<p class="MsoNormal">2016-03-03 03:37:53,546 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByPassivity:53] - Profile Action FilterFlowsByPassivity: Request does not have passive requirement, nothing to do<o:p></o:p></p>
<p class="MsoNormal">2016-03-03 03:37:53,547 - DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:53] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do<o:p></o:p></p>
<p class="MsoNormal">2016-03-03 03:37:53,548 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:257] - Profile Action SelectAuthenticationFlow: No specific Principals requested<o:p></o:p></p>
<p class="MsoNormal">2016-03-03 03:37:53,549 - DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:350] - Profile Action SelectAuthenticationFlow: Reusing active result authn/Password<o:p></o:p></p>
<p class="MsoNormal">2016-03-03 03:37:53,550 - DEBUG [net.shibboleth.idp.authn.impl.FinalizeAuthentication:144] - Profile Action FinalizeAuthentication: Canonical principal name established from session as 'dsmk'<o:p></o:p></p>
<p class="MsoNormal">2016-03-03 03:37:53,550 - DEBUG [net.shibboleth.idp.authn.impl.FinalizeAuthentication:186] - Profile Action FinalizeAuthentication: Request did not have explicit authentication requirements, result is accepted<o:p></o:p></p>
<p class="MsoNormal">2016-03-03 03:37:53,551 - DEBUG [net.shibboleth.idp.session.impl.UpdateSessionWithAuthenticationResult:205] - Profile Action UpdateSessionWithAuthenticationResult: Updating activity time on reused AuthenticationResult for flow authn/Pass<o:p></o:p></p>
<p class="MsoNormal">word in existing session 67003782855ebd58df489b229583ce286d0823782f986e4c6201ea8a5f7432ac<o:p></o:p></p>
<p class="MsoNormal">2016-03-03 03:37:53,552 - WARN [net.shibboleth.idp.session.impl.StorageBackedIdPSession:257] - Skipping update, AuthenticationResult for flow authn/Password in session 67003782855ebd58df489b229583ce286d0823782f986e4c6201ea8a5f7432ac not<o:p></o:p></p>
<p class="MsoNormal">found in storage<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">My NameID work touched the following files: attribute-filter.xml, attribute-resolver.xml, saml-nameid.xml, saml-nameid.properties, and relying-party.xml.  I have reviewed those and don’t see anything that should affect SSO behavior.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I get the same behavior with both the client and server memory session storage mechanisms so it does not appear to be a client session issue.  I also reviewed the web requests and I do see the cookies.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">My main question is how to approach debugging this type of issue as I did not see any debugging tips online around session store debugging. 
<o:p></o:p></p>
<p class="MsoNormal">  <o:p></o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal">David<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">PS:  The relying party.xml changes are only to add elements of the form:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">        <bean parent="RelyingPartyByName"<o:p></o:p></p>
<p class="MsoNormal">          c:relyingPartyIds="#{ {<o:p></o:p></p>
<p class="MsoNormal">            'https://www.concursolutions.com'<o:p></o:p></p>
<p class="MsoNormal">          } }"><o:p></o:p></p>
<p class="MsoNormal">          <property name="profileConfigurations"><o:p></o:p></p>
<p class="MsoNormal">            <list><o:p></o:p></p>
<p class="MsoNormal">              <bean parent="SAML2.SSO"<o:p></o:p></p>
<p class="MsoNormal">                p:signAssertions="always"<o:p></o:p></p>
<p class="MsoNormal">                p:encryptAssertions="false"<o:p></o:p></p>
<p class="MsoNormal">                p:encryptNameIDs="false"<o:p></o:p></p>
<p class="MsoNormal">                p:nameIDFormatPrecedence="#{{'urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified'}}"<o:p></o:p></p>
<p class="MsoNormal">                /><o:p></o:p></p>
<p class="MsoNormal">            </list><o:p></o:p></p>
<p class="MsoNormal">          </property><o:p></o:p></p>
<p class="MsoNormal">        </bean><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>