<div dir="ltr"><div>Having just switched our production IdP to V3, I'm monitoring the logs. I see several errors generated from requests like this:</div><br><div>







<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="gmail-s1">DEBUG [PROTOCOL_MESSAGE:121] - <br></span><span class="gmail-s1"><?xml version="1.0" encoding="UTF-8"?><br></span><span class="gmail-s1"><samlp:AuthnRequest<br></span><span class="gmail-s1">    AssertionConsumerServiceURL="<a href="https://community.uaf.edu/Shibboleth.sso/SAML2/POST">https://community.uaf.edu/Shibboleth.sso/SAML2/POST</a>"<br></span><span class="gmail-s1">    Destination="<a href="https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO">https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO</a>"<br></span><span class="gmail-s1">    ID="_7b673b4a261f8c734c5daf95676a2851"<br></span><span class="gmail-s1">    IssueInstant="2016-12-28T21:32:37Z"<br></span><span class="gmail-s1">    ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br></span><span class="gmail-s1">    Version="2.0" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><br></span><span class="gmail-s1">    <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://community.uaf.edu/shibboleth">https://community.uaf.edu/shibboleth</a></saml:Issuer><br></span><span class="gmail-s1">    <samlp:NameIDPolicy AllowCreate="1"/><br></span><span class="gmail-s1"></samlp:AuthnRequest></span></blockquote><div><br></div><div><br></div><div><br></div><div>triggered this error in V3:</div><div>







<p class="gmail-p1"><span class="gmail-s1">ERROR [org.opensaml.profile.action.impl.DecodeMessage:73] - Profile Action DecodeMessage: Unable to decode incoming request</span></p>
<p class="gmail-p1"><span class="gmail-s1">org.opensaml.messaging.decoder.MessageDecodingException: No SAMLRequest or SAMLResponse query path parameter, invalid SAML 2 HTTP Redirect message</span></p>
<p class="gmail-p1"><span class="gmail-s1"><span class="gmail-Apple-tab-span">  </span>at org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder.doDecode(HTTPRedirectDeflateDecoder.java:73)</span></p><p class="gmail-p1"><span class="gmail-s1"><br></span></p><p class="gmail-p1"><span class="gmail-s1">I then went back to my V2 logs, and was surprised (because I've received no user reports) to see parallel requests triggering this WARN:</span></p><p class="gmail-p1"><span class="gmail-s1"></span></p><div><p class="gmail-p1"><span class="gmail-s1">WARN [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:217] - No login context available, unable to proceed with authentication</span></p><p class="gmail-p1"><span class="gmail-s1">00:11:38.163 - DEBUG [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:209] - Processing incoming request</span></p><p class="gmail-p1"><span class="gmail-s1">00:11:38.163 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:339] - LoginContext key cookie was not present in request</span></p><p class="gmail-p1"><span class="gmail-s1">00:11:38.163 - WARN [edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine:217] - No login context available, unable to proceed with authentication</span></p></div><p class="gmail-p1"><span class="gmail-s1"><br></span></p><p class="gmail-p1"><span class="gmail-s1">but a few minutes later, a request that looks to me substantially the same:</span></p><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="gmail-s1">DEBUG [PROTOCOL_MESSAGE:121] - <br></span><span class="gmail-s1"><?xml version="1.0" encoding="UTF-8"?><br></span><span class="gmail-s1"><samlp:AuthnRequest<br></span><span class="gmail-s1">    AssertionConsumerServiceURL="<a href="https://community.uaf.edu/Shibboleth.sso/SAML2/POST">https://community.uaf.edu/Shibboleth.sso/SAML2/POST</a>"<br></span><span class="gmail-s1">    Destination="<a href="https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO">https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO</a>"<br></span><span class="gmail-s1">    ID="_8dcd8f6d80296b404cdd6a6c726b0496"<br></span><span class="gmail-s1">    IssueInstant="2016-12-28T21:50:02Z"<br></span><span class="gmail-s1">    ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br></span><span class="gmail-s1">    Version="2.0" xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><br></span><span class="gmail-s1">    <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://community.uaf.edu/shibboleth">https://community.uaf.edu/shibboleth</a></saml:Issuer><br></span><span class="gmail-s1">    <samlp:NameIDPolicy AllowCreate="1"/><br></span><span class="gmail-s1"></samlp:AuthnRequest></span></blockquote><p class="gmail-p1"><span class="gmail-s1">


















</span></p><p class="gmail-p1">is processed and leads to appropriate assertion issued by the V3 IdP.</p><p class="gmail-p1"><br>How should I interpret these results?</p><p class="gmail-p1">David Bantz</p><p class="gmail-p1">UA OIT IAM</p></div>










</div></div>