<div dir="ltr">Hi,<div><br></div><div>For Office365 web profile works with no issues, just that ECP profile does not seem to work, certainly it hits the IdP, hence Apache authentication is success and see entries in idp logs</div><div><br></div><div> relaying party I got below config</div><div><br></div><div><div><bean parent="RelyingPartyByName"  c:relyingPartyIds="urn:federation:MicrosoftOnline"></div><div>            <property name="profileConfigurations"></div><div>                <list></div><div>         <bean parent="SAML2.SSO" p:encryptAssertions="false" p:signAssertions="true" p:signResponses="false" p:encryptNameIDs="false" /></div><div>         <bean parent="SAML2.ECP" p:encryptAssertions="false" p:signAssertions="true" p:signResponses="false" p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" /></div><div>                </list></div><div>            </property></div><div>        </bean></div></div><div><br></div><div><br></div><div>and able to see below error in logs, anyone success getting ECP for office 365 with IdP 3.x, all working for me with IdP 2.4.X</div><div><br></div><div><br></div><div><p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><?xml version="1.0"
encoding="UTF-8"?><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"><soap11:Envelope
xmlns:soap11="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>"><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">   
<soap11:Header><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">       
<ecp:Response<span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">           
AssertionConsumerServiceURL="<a href="https://login.microsoftonline.com/login.srf">https://login.microsoftonline.com/login.srf</a>"<span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">           
soap11:actor="<a href="http://schemas.xmlsoap.org/soap/actor/next">http://schemas.xmlsoap.org/soap/actor/next</a>"<span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">           
soap11:mustUnderstand="1"
xmlns:ecp="urn:oasis:names:tc:SAML:2.0:profiles:SSO:ecp"/><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">   
</soap11:Header><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">   
<soap11:Body><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">       
<saml2p:Response<span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">           
Destination="<a href="https://login.microsoftonline.com/login.srf">https://login.microsoftonline.com/login.srf</a>"<span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">           
ID="_dssssbf856bafea5db12da9c4095df9eecf1"<span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">           
InResponseTo="_f0sssss1ec32e-2e9d-4bd8-98ee-d9846d855c3e"<span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">           
IssueInstant="2017-07-17T06:56:32.323Z" Version="2.0"
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">           
<saml2:Issuer
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://idpuatweb1.vu.edu.au/idp/shibboleth%3c/saml2:Issuer">https://myidp.x.y/idp/shibboleth</saml2:Issuer</a>><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">           
<saml2p:Status><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">               
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Requester"><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">                   
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:AuthnFailed"/><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">               
</saml2p:StatusCode><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">               
<saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">           
</saml2p:Status><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">       
</saml2p:Response><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)">   
</soap11:Body><span></span></span></p>

<p class="MsoNormal"><span style="font-size:11pt;font-family:Calibri,sans-serif;color:rgb(31,73,125)"></soap11:Envelope><span></span></span></p></div><div><br></div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Jul 11, 2017 at 9:51 PM, Matthew Slowe <span dir="ltr"><<a href="mailto:M.Slowe@kent.ac.uk" target="_blank">M.Slowe@kent.ac.uk</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="HOEnZb"><div class="h5">On 11/07/2017 07:19, Lalith Jayaweera wrote:<br>
> I configured the office 365 in IdP 3.3.x and mail (Web profile) works<br>
> with no issues,<br>
><br>
> However, ECP does not seem to work. Mobile phone mail setup....<br>
><br>
> Given same DNS of IdP, no change done in microsoft end.<br>
><br>
> However when I try ECP via mobile phone, I can't see any logs in IdP, as<br>
> if like not hit to IdP<br>
><br>
> Is there any way to track down or run some test clients to see where the<br>
> blockage is?<br>
<br>
</div></div>There weren't any simple ways to diagnose ECP issues last time I looked.<br>
<br>
I've published a simpleish way to make an ECP request into your IDP<br>
(taking Microsoft out of the loop) to check it's issuing a useful response:<br>
<br>
<a href="https://github.com/unikent-ms1/simple-soap-ecp-test" rel="noreferrer" target="_blank">https://github.com/unikent-<wbr>ms1/simple-soap-ecp-test</a><br>
<br>
Something to check is that the certificate in use on the HTTPS endpoint<br>
matches the signing certificate registered with Office365 for the IDP<br>
*and* is signed/validated by a mainstream CA (I think if Internet<br>
Explorer is happy with it then it should be fine).<br>
<span class="HOEnZb"><font color="#888888"><br>
--<br>
Matthew Slowe | Server Infrastructure Officer<br>
IT Infrastructure, Information Services, University of Kent<br>
Room S21, Cornwallis South<br>
Canterbury, Kent, CT2 7NZ, UK<br>
Tel: <a href="tel:%2B44%20%280%291227%20824265" value="+441227824265">+44 (0)1227 824265</a><br>
<br>
<a href="http://www.kent.ac.uk/is" rel="noreferrer" target="_blank">www.kent.ac.uk/is</a> | @UnikentUnseenIT | @UKCLibraryIt<br>
PGP: <a href="https://keybase.io/fooflington" rel="noreferrer" target="_blank">https://keybase.io/fooflington</a><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br></div>