<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from rtf -->
<style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<font face="Calibri" size="2"><span style="font-size:11pt;">
<div>Thanks for the response Scott.</div>
<div> </div>
<div>>Then the IdP isn't getting any user identity from the CAS client.</div>
<div> </div>
<div>I'm not seeing it redirect to CAS. On the first session that worked I see these in logs:</div>
<div style="padding-left:36pt;">15:41:39.119 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:240] - Redirecting user to authentication engine at
<a href="https://webapp.bgsu.edu:443/idp/AuthnEngine">https://webapp.bgsu.edu:443/idp/AuthnEngine</a></div>
<div style="padding-left:36pt;">...</div>
<div style="padding-left:36pt;">15:41:39.273 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.provider.RemoteUserLoginHandler:66] - <b>Redirecting to </b><a href="https://webapp.bgsu.edu:443/idp/Authn/RemoteUser"><font color="#0563C1"><b><u>https://webapp.bgsu.edu:443/idp/Authn/RemoteUser</u></b></font></a></div>
<div> </div>
<div>RemoteUser redirects to CAS. </div>
<div>But, on the failed attempt it never transfers to RemoteUser. Instead after it transfers to authentication engine it just logs this:</div>
<div style="padding-left:36pt;">[edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:178] - Incoming request contains a login context and indicates there was an error authenticating the principal, processing second leg of request</div>
<div> </div>
<div>Ted</div>
<div> </div>
</span></font>
</body>
</html>