<div dir="ltr"><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)">Good afternoon,</div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)">I'm an IdP operator trying to get SSO going with a vendor, and I am hoping someone can suggest some other things for me to check.  I apologize in advance for the length of the note.</div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)"><br></div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif">The vendor is Medicat.  Medicat is a member of InCommon, and according to the metadata, it looks like they have a couple dozen institutions they have already set up.  They say we are the only ones having this problem.  <span style="color:rgb(0,0,0);font-family:tahoma,sans-serif;font-size:small;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">The references to us in their metadata looks to be set up the same as their references to another school.  (</span></font><span style="color:rgb(0,0,0);font-family:tahoma,sans-serif">Their SP entityID is "<a href="https://sso.medicatconnect.com/shibboleth">https://sso.medicatconnect.com/shibboleth</a>" and our IdP entityID is "urn:mace:incommon:<a href="http://carleton.edu">carleton.edu</a>", for anyone wanting to look at the metadata.)</span></div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)">I'm using Chrome with the developer tools and SAML Chrome Panel 1.8.9 in particular to watch the flow through the browser.</div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)">When I go to their institution-specific URL, I am bounced to the InCommon WAYF.  After selecting our institution, I get bounced back to the vendor login URL with our entityID.  (I can't think of any other SP we use that uses the InCommon WAYF, but if it successfully determines our IdP entityID, I assume that this step is working completely.)</div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)">Next I come back from the vendor URL with a redirect to our IdP's HTTP-Redirect target and an AuthnRequest.  The AssertionConsumerServiceURL in the request matches the HTTP-POST binding in their metadata, the ProtocolBinding is HTTP-POST, the destination matches our IdPs's HTTP-Redirect target, and the issuer is their entityID.  This matches an AuthnRequest from a working SP (one that does not use the InCommon WAYF).<br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0)">(<span style="color:rgb(0,0,0);font-family:tahoma,sans-serif;font-size:small;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">During setup, the vendor kept asking me for our SSO login and logout URLs, and I reminded them that it was in the InCommon metadata.  They asked me to verify some of the values, which I did, but I think they are using Shibboleth SP so I don't know why they wouldn't just consume the data straight from the InCommon metadata.  </span>Feels like an opportunity to introduce trouble.)</div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif"><br></font></div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif">The next thing is a POST to their ACS URL with a signed, encrypted assertion.  The server immediately comes back with:</font></div><div class="gmail_default"><br></div><div class="gmail_default"><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px"><div class="gmail_default"><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif">xmltooling::IOException at (<a href="https://carleton.medicatconnect.com/Shibboleth.sso/SAML2/POST">https://carleton.medicatconnect.com/Shibboleth.sso/SAML2/POST</a>)</font></div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif"><br></font></div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif">Error reading request body from browser (2746).</font></div></div></blockquote><font color="#000000" face="tahoma, sans-serif"><br></font></div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif">So it's not a network timeout or anything like that.  I turned up logging for org.opensaml.saml.saml2.encryption.Encrypter, and the assertion before encryption has all of the attributes and values I expect.</font></div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif"><br></font></div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif">Besides their InCommon metadata, the only reference to them in our IdP configuration is to release an attribute that corresponds to our Student ID so that they can match against the nightly student import.  That's the only attribute they asked about, so I expect they aren't using any of the attributes in the default bundle we release to InCommon SPs.</font></div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif"><br></font></div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif">They asked me to verify their XML stanza for the student ID attribute:</font></div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif"><br></font></div><blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px"><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif"><Attribute name="urn:oid:1.3.6.1.4.1.13755.1.4" id="colleagueID"/></font><br></div></blockquote><font color="#000000" face="tahoma, sans-serif"><div><font color="#000000" face="tahoma, sans-serif"><br></font></div><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0);display:inline">​Our asserted attribute has the same name, but the id above (colleagueID) does not match the FriendlyName we assert (carlColleagueID).  That shouldn't matter, right?  I've asked them to change their attribute definition to match anyway.</div></font><div><font color="#000000" face="tahoma, sans-serif"><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0);display:inline"><br></div></font></div><div><font color="#000000" face="tahoma, sans-serif"><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0);display:inline">Thanks for reading all this way; any pointers would be appreciated.  I understand that the vendor has reverted to non-SSO for us, so for the moment I can't dig any deeper, but I'm hoping we can resume troubleshooting soon.</div></font></div><div><font color="#000000" face="tahoma, sans-serif"><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0);display:inline"><br></div></font></div><div><font color="#000000" face="tahoma, sans-serif"><div class="gmail_default" style="font-family:tahoma,sans-serif;color:rgb(0,0,0);display:inline">Best, -Les</div></font></div><div><div class="gmail_default"><font color="#000000" face="tahoma, sans-serif"><br></font></div><div><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><hr style="color:rgb(0,0,0);font-family:"times new roman","new york",times,serif;font-size:16px"><div style="color:rgb(0,0,0);font-family:"times new roman","new york",times,serif;font-size:16px;text-align:right"><span size="2" style="color:rgb(153,102,51);font-size:small">Les LaCroix '79 </span><span style="color:rgb(153,102,51)">|</span><span size="2" style="color:rgb(153,102,51);font-size:small"> </span><span size="2" style="color:rgb(153,102,51);font-size:small">Strategic Technologist<br></span><span size="2" style="color:rgb(153,102,51);font-size:small">Carleton College </span><span style="color:rgb(153,102,51)">|</span><span size="2" style="color:rgb(153,102,51);font-size:small"> 1 N. College St. </span><span style="color:rgb(153,102,51)">|</span><span size="2" style="color:rgb(153,102,51);font-size:small"> MS 3-ITS </span><span style="color:rgb(153,102,51)">|</span><span size="2" style="color:rgb(153,102,51);font-size:small"> Northfield, MN 55057<br></span><span size="2" style="color:rgb(153,102,51);font-size:small">507.222.5455 | <a href="https://calendar.google.com/calendar/embed?src=llacroix%40carleton.edu&ctz=America/Chicago" target="_blank">free/busy</a></span></div></div></div></div></div></div></div></div></div></div></div></div>
</div></div>