<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Menlo;
        panose-1:0 0 0 0 0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
code
        {mso-style-priority:99;
        font-family:"Courier New";}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
p.gmail-p1, li.gmail-p1, div.gmail-p1
        {mso-style-name:gmail-p1;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
span.gmail-s1
        {mso-style-name:gmail-s1;}
span.im
        {mso-style-name:im;}
span.EmailStyle22
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
span.EmailStyle23
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:1661692448;
        mso-list-template-ids:1126826492;}
@list l0:level1
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level3
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level4
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level5
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level6
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level7
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level8
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level9
        {mso-level-number-format:bullet;
        mso-level-text:;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal" style="margin-bottom:1.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thank you sir,  that is surprising…  It is my personal workstation and I cannot imagine how it could be changing its IP address… 
 That should be static for the time of my connection to the network…  Not aware of any virtualization being done on behalf of my session(s).  There may be something going on with the way the application web server is managing/building my session with it when
 I attempt to invoke the target URL. I do not know, but again, I can’t imagine how that would be reflected as an ip address change on behalf of my PC…  Also, those IP addresses are from the corporate network and the application is running in the cloud with
 a completely different range of addresses.  Not sure that you would be interested in this, but, it would take a bit to explain it all.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-bottom:1.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-bottom:1.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Now, the reason I think the consistentAddress parm is the problem is that I think this is actually an application design issue.  What
 is happening is that the application has a ‘world’ facing web server.  This web server takes care of being the middleman for the traffic into the application (SAS).  The application has a compute service that runs on a separate server.  The web service authenticates
 you on one server and all the session info is set up for that server.  Then the application immediately passes you to the compute server which is the actual target the user was shooting for.  This function will be starting processes under the users ID on that
 server and thus it too needs to authenticate you.  When that is attempted with the current cookie, it is invalidated because the ip address is different since it’s a different server.  This triggers a new call to the IdP which recognizes (and approves of)
 the attached cookie/token and just turns it right back around to the SP which again attempts to open a session with the compute server  and around and around we go….<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-bottom:1.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-bottom:1.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Are you thinking that I have something else going on?  I was unaware that the IP addresses in that log entry for the create sessions
 was (supposedly) the IP address of my device/browser until a post from David mentioned it a short time ago.  SO, no matter what those addresses are, I don’t think I know what’s going on after all…  It *<b>could</b>* be that the GCP LB is presenting a generated
 IP address (in a NAT sense so to speak) for my sessions as the transaction travels through it, but I don’t think that is the case.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-bottom:1.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-bottom:1.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I really thought that the looping was caused by the 2 relevant SAS servers and the authentication occurring on one before the session
 was passed to the second.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-bottom:1.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-bottom:1.0pt"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Gee thanks…  I thought I had it all figured out and here you go throwing a wrench into the middle of all my (supposedly) clean logic… 
 I will dig into this tomorrow.  Can you suggest which logs would be best for evaluating this?  Or perhaps just Fiddler and walking through all the traffic as it passes through?</span><span style="font-size:9.0pt;font-family:"Calibri",sans-serif;color:#44546A"><o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Courier New";color:#1F497D"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users <users-bounces@shibboleth.net>
<b>On Behalf Of </b>Lipscomb, Gary<br>
<b>Sent:</b> Wednesday, June 6, 2018 8:25 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> RE: [EXTERNAL] Re: Problem implementing Shibboleth/SAML to authenticate users for Statistical Analysis Systems (SAS)<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span lang="EN-AU"><quote>The consistentAddress setting was indeed the culprit, so I don’t want to waste other’s time in the group,/quote><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-AU"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-AU">That’s not the culprit. You need to find out why your client’s addresses are constantly changing. You are only masking the problem by turning that off.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-AU"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-AU">Gary<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-AU" style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users [<a href="mailto:users-bounces@shibboleth.net">mailto:users-bounces@shibboleth.net</a>]
<b>On Behalf Of </b>O'Quinn, Dennis<br>
<b>Sent:</b> Thursday, 7 June 2018 10:19<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Subject:</b> Re: [EXTERNAL] Re: Problem implementing Shibboleth/SAML to authenticate users for Statistical Analysis Systems (SAS)<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">David (and everyone else), I really want to thank everyone for their replies.  The consistentAddress setting was indeed the culprit, so I don’t want to waste other’s time in the group.
<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:12.0pt;margin-left:.5in">
<span lang="EN-AU">Also, I have said all I need to say about my feedback to Scott. This is something that I would usually do on a private channel, but since it was already published on the public channel and as I said before, I had seen such comments in many
 other threads, I felt a public response was warranted.  I hope it is constructive feedback that is given consideration. I did not give it as judgement. I do not feel the need to live up to or down to anyone else’s opinion and I expect no one to do any different
 with me.  Everyone is in this world to live up to their own expectations and opinion. My point was that it could be hurting the group and *that* is what should be considered. <o:p></o:p></span></p>
<div id="AppleMailSignature">
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">Sent from my iPhone<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:12.0pt;margin-left:.5in">
<span lang="EN-AU"><br>
On Jun 6, 2018, at 7:52 PM, IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<o:p></o:p></span></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">Dear Dennis O'Quinn, 
<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><br>
Like others I detected your rising level of frustration in this thread. I hesitate to add any stress and lack confidence I can explain anything better than Scott. But let me perhaps foolishly try. 
<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:12.0pt;margin-left:.5in">
<span lang="EN-AU">The issue that seems clear from some of the log messages you shared is that the IP address of the client workstation appears to shift at every interaction. Those entries in the SP logs indicating sessions created and destroyed - like<o:p></o:p></span></p>
<p class="gmail-p1" style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt">
<span class="gmail-s1"><span lang="EN-AU" style="font-size:8.5pt;font-family:"Menlo",serif;color:black">new session created: ID (_d8a65139b583fb1e0b5382d39c3078d5) IdP (urn:mace:incommon:<a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__antispam.csu.edu.au-3A32224_-3FdmVyPTEuMDAxJiY5ZDY2MGU1NDZjOWY1MWJkOT01QjE4N0E0N18zNTg2N18yOTAwXzEmJmMyMThlZjI3ODAxZTc4Mz0yMjMyJiZ1cmw9aHR0cHMlM0ElMkYlMkZ1cmxkZWZlbnNlJTJFcHJvb2Zwb2ludCUyRWNvbSUyRnYyJTJGdXJsJTNGdSUzRGh0dHAtM0ElNUYlNUZhbGFza2ElMkVlZHUlMjZhbXAlM0JkJTNERHdNRmFRJTI2YW1wJTNCYyUzRE10Z1FFQU1RR3Fla2pUamlBaGt1ZFElMjZhbXAlM0JyJTNEbW42RGVCdDFuajhPcXgwNnBkSUswJTVGbjVFZks2RmVWSGdkakJOcGNoeXJvJTI2YW1wJTNCbSUzRHFJOU1FdFlva0RLNHVRaUU3cUtCWmp1dS1tbTdkUmhOa0YyQUJqYWY0Y3clMjZhbXAlM0JzJTNEWUoteUNFZDR1aGFqNlJFRXFOUVJXbGZlb0NIeU5VenpBcCU1RlNFWmpnS05RJTI2YW1wJTNCZSUzRA-3D-3D&d=DwMGaQ&c=MtgQEAMQGqekjTjiAhkudQ&r=mn6DeBt1nj8Oqx06pdIK0_n5EfK6FeVHgdjBNpchyro&m=UmAHpRUS0t3fUZgWxX35mRWDACFqDvYO6incJwTOUUI&s=DOBnIhlN4klW-gOTsYBNKukpTQOz2r0lhSinYogzfQQ&e=">alaska.edu</a>)
 Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (137.229.6.126) -</span></span><span lang="EN-AU" style="font-size:8.5pt;font-family:"Menlo",serif;color:black"><o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">are providing, at the end of the log entry, the IP address of the client - not the service, not the IdP, but the client workstation.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">That SP session and the cookie in the client browser are tied to that IP address but apparently the very next time the client goes to the service, the SP notices the client IP address does not
 match the IP address in the cookie, and destroys that session.  <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">How and why the client workstation keeps presenting different IP addresses is not something the IdP or the SP have any control of, which is why folks on this list aren't able to provide you a
 recipe of how to correct the problem you are experiencing. <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">One alternative in the thread you may have missed is a reference to documentation on configuring the SP to "not care" about changing IP address: <a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__antispam.csu.edu.au-3A32224_-3FdmVyPTEuMDAxJiY5ZDY2MGU1NDZjOWY1MWJkOT01QjE4N0E0N18zNTg2N18yOTAwXzEmJmMyMThlZjI3ODAxZTc4Mz0yMjMyJiZ1cmw9aHR0cHMlM0ElMkYlMkZ1cmxkZWZlbnNlJTJFcHJvb2Zwb2ludCUyRWNvbSUyRnYyJTJGdXJsJTNGdSUzRGh0dHBzLTNBJTVGJTVGd2lraSUyRXNoaWJib2xldGglMkVuZXQlNUZjb25mbHVlbmNlJTVGZGlzcGxheSU1RlNISUIyJTVGTmF0aXZlU1BTZXNzaW9ucyUyNmFtcCUzQmQlM0REd01GYVElMjZhbXAlM0JjJTNETXRnUUVBTVFHcWVralRqaUFoa3VkUSUyNmFtcCUzQnIlM0RtbjZEZUJ0MW5qOE9xeDA2cGRJSzAlNUZuNUVmSzZGZVZIZ2RqQk5wY2h5cm8lMjZhbXAlM0JtJTNEcUk5TUV0WW9rREs0dVFpRTdxS0JaanV1LW1tN2RSaE5rRjJBQmphZjRjdyUyNmFtcCUzQnMlM0RnVjZLN0pqRnUzaiU1Ri00Wkp0Z1JUZy1wcG9RRzJYeWllRDBHOFhUdGU0YjQlMjZhbXAlM0JlJTNE&d=DwMGaQ&c=MtgQEAMQGqekjTjiAhkudQ&r=mn6DeBt1nj8Oqx06pdIK0_n5EfK6FeVHgdjBNpchyro&m=UmAHpRUS0t3fUZgWxX35mRWDACFqDvYO6incJwTOUUI&s=9W-b3THSpaeEF-t6bpI5au-wcJ1LtBJowrx9VlhAyUk&e=">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessions</a>:<o:p></o:p></span></p>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0in;margin-bottom:5.0pt">
<p class="MsoNormal" style="margin-left:.5in"><code><span lang="EN-AU" style="font-size:10.5pt;color:#333333;background:white">consistentAddress</span></code><span lang="EN-AU" style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333;background:white">(boolean)
 (default is true)</span><span lang="EN-AU"> <o:p></o:p></span></p>
<ul type="disc">
<li class="MsoNormal" style="color:#333333;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo2;background:white">
<span lang="EN-AU" style="font-size:10.5pt;font-family:"Arial",sans-serif">When true, the SP will remember the IP address used when creating a session and ensure that all subsequent access associated with this session come from the same address. This can help
 protect against cookie theft and is less likely than the </span><code><span lang="EN-AU" style="font-size:10.0pt">checkAddress</span></code><span lang="EN-AU" style="font-size:10.5pt;font-family:"Arial",sans-serif"> setting to block legitimate access.<o:p></o:p></span></li></ul>
</blockquote>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">Apologies in advance if this is unhelpful.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">David Bantz<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">UA OIT IAM<o:p></o:p></span></p>
</div>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">On Wed, Jun 6, 2018 at 1:25 PM, O'Quinn, Dennis <<a href="mailto:DENNIS_OQUINN@homedepot.com" target="_blank">DENNIS_OQUINN@homedepot.com</a>> wrote:<o:p></o:p></span></p>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0in;margin-bottom:5.0pt">
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">Thank you for your response.  I get your loyalty and his dedication.  And yes, I am *brand* new to the community, to Shibboleth, and to IdP/SP/SAML in general.<br>
<br>
I have thanked him already (early on) when he responded so quickly to my postings,  and I gathered my issues was way beneath his level of expertise.<br>
<br>
However, to talk down to someone, who he doesn't know and in this case is every bit as old as he is, the way he did, and, the way I have seen him do in numerous other replies as I researched before even joining and wasting the user communities time, deserves
 feedback.<br>
<br>
This is *especially* true given that people like me are essentially customers in a sense.<br>
<br>
For me, I was joining a user group.  Not Scott's personal support service.  I am fine with terse and short.  I am fine if he gives me what he does and then moves on (which I had thought had already happened).<br>
<br>
I re-submitted my question because I had finally found out how to trace and track data and I wanted to put as much information there to make it as easy as I could for someone to assist me.<br>
<br>
I was impressed with his initial responsiveness, though, his advice was way over my head at the time and I had no frame of reference to be able to understand what he was saying.  I was trying to come back and ask more, but, I needed to even know what I was
 asking.<br>
<br>
I have already responded to someone else on a private communication about this that his attitude will hurt this project in the long run, and I believe that.<br>
<br>
I am obviously not afraid to speak my mind and offer what I feel to be deserved feedback, but, many others are.<br>
<br>
They will not come to your group only to have someone imply that they are idiots for not listening to what they are being told, when actually, they are new to the software and do not have enough knowledge or frame of reference against which to apply and make
 use of the responses.<br>
<br>
And then (as I have seen in quite a few responses from Scott specifically), when they come back for clarification or more discussion, it gets even worse.<br>
<br>
NOTE: This feedback is meant to be constructive and is not a triggered response.  If you haven't seen the type of responses that I am refereing to, then I would be surprised.  They were all over the place in the Shibboleth user group responses I was getting
 via my Google searches.<br>
<br>
<span class="im">-----Original Message-----</span><br>
<span class="im">From: John Dennis <<a href="mailto:jdennis@redhat.com">jdennis@redhat.com</a>></span><br>
<span class="im">Sent: Wednesday, June 6, 2018 4:15 PM</span><br>
<span class="im">To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>>; O'Quinn, Dennis <<a href="mailto:DENNIS_OQUINN@homedepot.com">DENNIS_OQUINN@homedepot.com</a>></span><br>
<span class="im">Subject: [EXTERNAL] Re: Problem implementing Shibboleth/SAML to authenticate users for Statistical Analysis Systems (SAS)</span><br>
<br>
<span class="im">On 06/06/2018 03:24 PM, O'Quinn, Dennis wrote:</span><br>
<span class="im">> The only thing I can say to that last response is 'Wow'....</span><br>
<span class="im">></span><br>
<span class="im">> Your previous responses were none too clear to a novice who does not know this environment and you did not reply to one of my key questions, which may have helped me along in the right direction, which was asking for a definition/perspective
 of the word 'client' in one of your earlier responses since the 'client' in this environment could be one of several entities depending on perspective....</span><br>
<span class="im">></span><br>
<span class="im">> Also, I don't recall addressing my question to you (and I checked).</span><br>
<span class="im">></span><br>
<span class="im">> I had the distinct impression from your previous tone that you had already blown me off.</span><br>
<span class="im">></span><br>
<span class="im">> I was under the impression that I was posting to a user community associated with Shibboleth where users could share and grow knowledge together.</span><br>
<span class="im">></span><br>
<span class="im">> Since you know so much and are apparently so annoyed with other people's ignorance (which I have noted on more that one post to other people), why do you even respond to these?</span><br>
<span class="im">></span><br>
<span class="im">> And speaking of tone, if you wish to forward this project and have it go somewhere, your tone in dealing with others that do not know this software (or the IdP/SP/SAML environment) may be something you should think about.</span><br>
<span class="im">></span><br>
<span class="im">> Otherwise, your user community will just say screw it and use something else (as I would if I weren't already so deep into it).</span><br>
<br>
<span class="im">We all make mistakes from time to time and sometimes we just don't have the context to evaluate. I believe you're new to the mailing list so you may not realize Scott is not only the primary author of Shibboleth and member of the OASIS Technical
 Committee that defines the SAML standard but IMHO Scott represents some of the best qualities in an open source community I've seen in my 30+ years of open source work. For years Scott has promptly responded with useful help to almost every message on this
 list. As a matter of fact I'm significantly impressed Scott has been able to do this for so long and still get other work done. Only in the last year have I seen him pull back a bit and only because he is human and cannot support everyone 24/7 out of the kindness
 of his heart. I applaud open source heroes like Scott and everyone involved in the Shibboleth project. I'm impressed.</span><br>
<br>
<span class="im">If you spend a bit of time in other open source communities you'll appreciate how good the Shibboleth community is in comparison.</span><br>
<br>
<span class="im">Kudos to everyone involved.</span><br>
<br>
<br>
<span class="im">--</span><br>
<span class="im">John Dennis</span><br>
<br>
<span class="im">________________________________</span><br>
<br>
<span class="im">The information in this Internet Email is confidential and may be legally privileged. It is intended solely for the addressee. Access to this Email by anyone else is unauthorized. If you are not the intended recipient, any disclosure, copying,
 distribution or any action taken or omitted to be taken in reliance on it, is prohibited and may be unlawful. When addressed to our clients any opinions or advice contained in this Email are subject to the terms and conditions expressed in any applicable governing
 The Home Depot terms of business or client engagement letter. The Home Depot disclaims all responsibility and liability for the accuracy and content of this attachment and for any damages or losses arising from any inaccuracies, errors, viruses, e.g., worms,
 trojan horses, etc., or other items of a destructive nature, which may be contained in this attachment and shall not be liable for direct, indirect, consequential or special damages in connection with this e-mail message or its at</span><br>
<span class="im"> tachment.</span><o:p></o:p></span></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">-- <br>
For Consortium Member technical support, see <a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__antispam.csu.edu.au-3A32224_-3FdmVyPTEuMDAxJiY5ZDY2MGU1NDZjOWY1MWJkOT01QjE4N0E0N18zNTg2N18yOTAwXzEmJmMyMThlZjI3ODAxZTc4Mz0yMjMyJiZ1cmw9aHR0cHMlM0ElMkYlMkZ1cmxkZWZlbnNlJTJFcHJvb2Zwb2ludCUyRWNvbSUyRnYyJTJGdXJsJTNGdSUzRGh0dHBzLTNBJTVGJTVGd2lraSUyRXNoaWJib2xldGglMkVuZXQlNUZjb25mbHVlbmNlJTVGeCU1RmNvRkFBZyUyNmFtcCUzQmQlM0REd01GYVElMjZhbXAlM0JjJTNETXRnUUVBTVFHcWVralRqaUFoa3VkUSUyNmFtcCUzQnIlM0RtbjZEZUJ0MW5qOE9xeDA2cGRJSzAlNUZuNUVmSzZGZVZIZ2RqQk5wY2h5cm8lMjZhbXAlM0JtJTNEcUk5TUV0WW9rREs0dVFpRTdxS0JaanV1LW1tN2RSaE5rRjJBQmphZjRjdyUyNmFtcCUzQnMlM0RxOWVHUHJvZDhMUkViZUclNUZ5LTZuTFlYemJaWDdhLU80Mlo3NDJHTGVneTQlMjZhbXAlM0JlJTNE&d=DwMGaQ&c=MtgQEAMQGqekjTjiAhkudQ&r=mn6DeBt1nj8Oqx06pdIK0_n5EfK6FeVHgdjBNpchyro&m=UmAHpRUS0t3fUZgWxX35mRWDACFqDvYO6incJwTOUUI&s=kpvqG4m8Gbyy2qCeORVAMWYESsW5Udh9WhUpFCiwmlo&e=" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></span></p>
</div>
</div>
</blockquote>
</div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
</div>
</div>
</blockquote>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU">-- <br>
For Consortium Member technical support, see <a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__antispam.csu.edu.au-3A32224_-3FdmVyPTEuMDAxJiY5ZDY2MGU1NDZjOWY1MWJkOT01QjE4N0E0N18zNTg2N18yOTAwXzEmJmMyMThlZjI3ODAxZTc4Mz0yMjMyJiZ1cmw9aHR0cHMlM0ElMkYlMkZ1cmxkZWZlbnNlJTJFcHJvb2Zwb2ludCUyRWNvbSUyRnYyJTJGdXJsJTNGdSUzRGh0dHBzLTNBJTVGJTVGd2lraSUyRXNoaWJib2xldGglMkVuZXQlNUZjb25mbHVlbmNlJTVGeCU1RmNvRkFBZyUyNmFtcCUzQmQlM0REd0lDQWclMjZhbXAlM0JjJTNETXRnUUVBTVFHcWVralRqaUFoa3VkUSUyNmFtcCUzQnIlM0RtbjZEZUJ0MW5qOE9xeDA2cGRJSzAlNUZuNUVmSzZGZVZIZ2RqQk5wY2h5cm8lMjZhbXAlM0JtJTNEcUk5TUV0WW9rREs0dVFpRTdxS0JaanV1LW1tN2RSaE5rRjJBQmphZjRjdyUyNmFtcCUzQnMlM0RxOWVHUHJvZDhMUkViZUclNUZ5LTZuTFlYemJaWDdhLU80Mlo3NDJHTGVneTQlMjZhbXAlM0JlJTNE&d=DwMGaQ&c=MtgQEAMQGqekjTjiAhkudQ&r=mn6DeBt1nj8Oqx06pdIK0_n5EfK6FeVHgdjBNpchyro&m=UmAHpRUS0t3fUZgWxX35mRWDACFqDvYO6incJwTOUUI&s=YFdVxD3keRZ1XJ8TePQmxQnmGHSqR--BZ9VS7YOoMR0&e=">
https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=MtgQEAMQGqekjTjiAhkudQ&r=mn6DeBt1nj8Oqx06pdIK0_n5EfK6FeVHgdjBNpchyro&m=qI9MEtYokDK4uQiE7qKBZjuu-mm7dRhNkF2ABjaf4cw&s=q9eGProd8LREbeG_y-6nLYXzbZX7a-O42Z742GLegy4&e=</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></span></p>
</div>
</blockquote>
</div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU"><o:p> </o:p></span></p>
<div style="margin-left:.5in">
<div class="MsoNormal" align="center" style="text-align:center"><span lang="EN-AU">
<hr size="2" width="100%" align="center">
</span></div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-AU" style="font-size:7.5pt;font-family:"Arial",sans-serif;color:gray"><br>
The information in this Internet Email is confidential and may be legally privileged. It is intended solely for the addressee. Access to this Email by anyone else is unauthorized. If you are not the intended recipient, any disclosure, copying, distribution
 or any action taken or omitted to be taken in reliance on it, is prohibited and may be unlawful. When addressed to our clients any opinions or advice contained in this Email are subject to the terms and conditions expressed in any applicable governing The
 Home Depot terms of business or client engagement letter. The Home Depot disclaims all responsibility and liability for the accuracy and content of this attachment and for any damages or losses arising from any inaccuracies, errors, viruses, e.g., worms, trojan
 horses, etc., or other items of a destructive nature, which may be contained in this attachment and shall not be liable for direct, indirect, consequential or special damages in connection with this e-mail message or its attachment.</span><span lang="EN-AU"><o:p></o:p></span></p>
</div>
<br>
<hr>
<font face="Arial" color="Gray" size="1"><br>
The information in this Internet Email is confidential and may be legally privileged. It is intended solely for the addressee. Access to this Email by anyone else is unauthorized. If you are not the intended recipient, any disclosure, copying, distribution
 or any action taken or omitted to be taken in reliance on it, is prohibited and may be unlawful. When addressed to our clients any opinions or advice contained in this Email are subject to the terms and conditions expressed in any applicable governing The
 Home Depot terms of business or client engagement letter. The Home Depot disclaims all responsibility and liability for the accuracy and content of this attachment and for any damages or losses arising from any inaccuracies, errors, viruses, e.g., worms, trojan
 horses, etc., or other items of a destructive nature, which may be contained in this attachment and shall not be liable for direct, indirect, consequential or special damages in connection with this e-mail message or its attachment.<br>
</font>
</body>
</html>