<div dir="ltr">Scott,<div><br></div><div>Would this be enough from our signature debug log? I've attached the client's metadata as well.<div><br></div><div><div>----- BEGIN SIGNATURE DEBUG -----</div><div><Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion" ID="_2aa7d588-cdcb-4f3a-9b92-81b71f8d32c1" IssueInstant="2016-04-04T20:52:25.579Z" Version="2.0"><Issuer><a href="http://login.apus.edu/adfs/services/trust">http://login.apus.edu/adfs/services/trust</a></Issuer><Subject><NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"><a href="mailto:cd839@apus.edu">cd839@apus.edu</a></NameID><SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><SubjectConfirmationData InResponseTo="_e2a08c94dafd313228641bbda821c989" NotOnOrAfter="2016-04-04T20:57:25.579Z" Recipient="<a href="https://www.digitalmeasures.com/Shibboleth.sso/SAML2/POST">https://www.digitalmeasures.com/Shibboleth.sso/SAML2/POST</a>"></SubjectConfirmationData></SubjectConfirmation></Subject><Conditions NotBefore="2016-04-04T20:52:25.579Z" NotOnOrAfter="2016-04-04T21:52:25.579Z"><AudienceRestriction><Audience><a href="https://www.digitalmeasures.com/shibboleth-sp/">https://www.digitalmeasures.com/shibboleth-sp/</a></Audience></AudienceRestriction></Conditions><AttributeStatement><Attribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><AttributeValue><a href="mailto:cd839@apus.edu">cd839@apus.edu</a></AttributeValue></Attribute></AttributeStatement></Assertion></div><div>----- END SIGNATURE DEBUG -----</div></div><div><br></div><div>This message corresponds to the previously provided log output.</div><div><br></div><div>We're on 2.5.2 because that's the version available in Ubuntu 14.04's package repositories; an upgrade would be a significant challenge. Even the upcoming 16.04 LTS release only packages 2.5.3. Our SP is used by clients from hundreds of universities daily, so we're hesitant to roll our own package at the risk of stability.</div><div><br></div><div>All our other clients are members of InCommon or other country-specific federations; this particular client had issues that necessitated us consuming their own self-published metadata.</div><div><br></div><div>Would you be willing/able to test it against 2.5.6, just to see if it works with the most recent version?</div><div><br></div><div>Many thanks,</div><div>Scott Severtson</div><div>Digital Measures</div><div><br></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Apr 5, 2016 at 3:09 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">> Has anyone run into the blank session ID issue? Anything else we or they<br>
> should be doing to debug the problem?<br>
<br>
I can't really think offhand how it's possible for that to happen, but it would take some code review, and I won't spend that time unless you reproduce the issue on the supported version (and then you can feel free to file a bug on it).<br>
<br>
A full log trace might give me a hint about it. Presumably it's got something to do with the message, so that's the place to look.<br>
<br>
I would have to run a sample message (without encryption on ideally) through the code to debug it, I just need the metadata being used to provision a test. With encryption on it would not work unless I had the key, so that's not ideal. I don't think it would have any impact on the issue whether it's on or off, but if you can't get a non-encrypted test from the IdP, that doesn't leave good options apart from generating a dummy keypair for a test that you could attach to a bug report.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>