<div dir="ltr"><span style="font-size:12.8px">All,</span><div style="font-size:12.8px"><br></div><div style="font-size:12.8px">We're trying to set up our Shibboleth SP 2.5.2 to work with a client's ADFS server, and have been running into problems.<div><br></div><div>In our logs, we see events like:</div><div>---</div><div><div>2016-04-04 15:52:26 INFO Shibboleth-TRANSACTION [155]: New session (ID: ) with (applicationId: default) for principal from (IdP: <a href="http://login.apus.edu/adfs/services/trust" target="_blank">http://login.apus.edu/adfs/services/trust</a>) at (ClientAddress: 172.76.24.18) with (NameIdentifier: none) using (Protocol: urn:oasis:names:tc:SAML:2.0:protocol) from (AssertionID: )</div><div>2016-04-04 15:52:26 INFO Shibboleth-TRANSACTION [155]: Cached the following attributes with session (ID: ) for (applicationId: default) {</div><div>2016-04-04 15:52:26 INFO Shibboleth-TRANSACTION [155]: }</div></div><div>---</div><div><br></div><div>The strange part is that the session ID is logged as blank. No errors are reported. Signature Debugging is enabled, and shows that the XML is being decrypted correctly. </div><div><br></div><div><br></div><div>The client transformed their metadata using "Federation Metadata Manager for ADFS" (<a href="https://sourceforge.net/projects/femma/" target="_blank">https://sourceforge.net/projects/femma/</a>); the modified metadata is currently at:</div><div><br></div><div><a href="https://login.apus.edu/adfs/FederationMetadata/2007-06/Shibboleth/FederationMetadata.xml" target="_blank">https://login.apus.edu/adfs/FederationMetadata/2007-06/Shibboleth/FederationMetadata.xml</a><br></div><div><br></div><div>Has anyone run into the blank session ID issue? Anything else we or they should be doing to debug the problem?</div><div><br></div><div>Thanks,</div><div>Scott Severtson</div><div>Digital Measures</div></div></div>