<div dir="ltr">in idp log:<div>

<pre id="gmail-hterm:copy-to-clipboard-source" style="color:rgb(0,0,0);text-decoration-style:initial;text-decoration-color:initial">ERROR [org.jasig.cas.client.util.XmlUtils:194] - The markup in the document following the root element must be well-formed.
org.xml.sax.SAXParseException: The markup in the document following the root element must be well-formed.</pre><pre id="gmail-hterm:copy-to-clipboard-source" style="color:rgb(0,0,0);text-decoration-style:initial;text-decoration-color:initial">Looking at cas-client-3.4.1 source, error above is happening for each of the XmlUtils.getTextForElement which eventually produces:</pre><pre id="gmail-hterm:copy-to-clipboard-source" style="color:rgb(0,0,0);text-decoration-style:initial;text-decoration-color:initial"><pre id="gmail-hterm:copy-to-clipboard-source" style="text-decoration-style:initial;text-decoration-color:initial">ERROR [net.unicon.idp.externalauth.ShibcasAuthServlet:109] - Ticket validation failed, returning InvalidTicket
org.jasig.cas.client.validation.TicketValidationException: No principal was found in the response from the CAS server.</pre>Now to figure out what cas is sending back.</pre><pre id="gmail-hterm:copy-to-clipboard-source" style="color:rgb(0,0,0);text-decoration-style:initial;text-decoration-color:initial">Thanks.</pre><pre id="gmail-hterm:copy-to-clipboard-source" style="color:rgb(0,0,0);text-decoration-style:initial;text-decoration-color:initial">-psv</pre><pre id="gmail-hterm:copy-to-clipboard-source" style="color:rgb(0,0,0);text-decoration-style:initial;text-decoration-color:initial"></pre></div></div><br><div class="gmail_quote"><div dir="ltr">On Sat, Jul 21, 2018 at 4:36 AM Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Pablo Vidaurri <<a href="mailto:psvidaurri@gmail.com" target="_blank">psvidaurri@gmail.com</a>> [2018-07-20 23:09]:<br>
> I am trying to do SSO using CAS and having shib 3 as SAML provider.<br>
<br>
Note that the Shibboleth IDP speaks CAS we well, so ideally you could<br>
replace your CAS server and use just one system for all use-cases.<br>
<br>
> SAML response reported an IdP error.<br>
> <br>
> Error from identity provider:<br>
<br>
Well, what does the Identity Provider's logs say, then?<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>