<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b style=" font-family: "Times New Roman"; font-size: medium">Cantor, Scott</b><span style=" font-family: "Times New Roman"; font-size: medium; background-color: rgb(255, 255, 255); display: inline !important"><span> </span></span><a href="mailto:users%40shibboleth.net?Subject=Re:%20Re%3A%20Shibboleth%20SP%20500%20after%20processing%20valid%20SAML%20response%20and%0A%20assertion&In-Reply-To=%3C6C0AA522-4850-4783-A999-27F22C6BBA32%40osu.edu%3E" title="Shibboleth SP 500 after processing valid SAML response and assertion" style="font-family: "Times New Roman"; font-size: medium">cantor.2
at osu.edu<span> </span></a><br style=" font-family: "Times New Roman"; font-size: medium">
<i style=" font-family: "Times New Roman"; font-size: medium">Mon Oct 1 14:16:39 EDT 2018</i><br>
<pre>><i> As mentioned, since the Assertion and Response are SAML-valid, I would expect an error in the logs if there is an issue
</i>><i> with the coherence of the request. I'm looking for any suggestion to the investigate further this issue.
</i>
I would be very surprised if nothing is logged but be that as it may I think the problem is the OneTimeUse Condition in there, which is not processed/accepted by the default policy rules the SP ships with.
-- Scott
</pre>
Thank you Scott, after the customer changed the time on its server for testing purposes, we figured out that their
<span style=" font-size: 16px; background-color: rgb(255, 255, 255); display: inline !important">
AuthnInstant<span> in the </span></span>AuthnStatement had 1h difference with the Response and Assertion's IssueInstant.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
It looks like in this case, the SP did not emit any error or warning, but simply dropped the assertion. Is this expected behavior ? Can I assume that when no error or warning is in the logs, then the issue is in the coherence of the response ? Or is it such
an edge case that this is not dealt with in the logs ?</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Here are the logs' timestamps for reference: </div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
2018-10-01 11:45:43-0700 DEBUG OpenSAML.MessageDecoder.SAML2POST [10]: decoded SAML message:<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<div>saml2p:Response IssueInstant="2018-10-01T18:43:57.389Z"<br>
</div>
<div>saml2:Assertion IssueInstant="2018-10-01T18:43:51.928Z" <br>
</div>
<div>saml2:SubjectConfirmationData NotOnOrAfter="2018-10-01T19:48:51.928Z"<br>
</div>
<div>AuthnStatement AuthnInstant="2018-10-01T19:43:51.928Z" SessionNotOnOrAfter="2018-10-01T19:58:51.928Z"><br>
</div>
<div><br>
</div>
<div>We managed to test a successful login by fiddling with test servers' time to confirm this is the issue.</div>
<div><br>
</div>
<span></span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thomas<br>
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="signature">
<div id="divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p style="margin-top: 0px; margin-bottom: 0px;">-- </p>
<p style="margin-top: 0px; margin-bottom: 0px;">Thomas Blanchard</p>
<div style="margin-top: 0px; margin-bottom: 0px;"><span>LinkedIn Learning & Lynda SRE</span><span></span></div>
</div>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Thomas Blanchard<br>
<b>Sent:</b> Monday, October 1, 2018 13:58<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Shibboleth SP 500 after processing valid SAML response and assertion</font>
<div> </div>
</div>
<meta content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none">
<!--
p
{margin-top:0;
margin-bottom:0}
-->
</style>
<div dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Hello everyone, </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
I'm having a really troubling issue with a customer getting 500 during the SAML Response processing after passing a valid Response and Assertion (I validated both the whole response and the assertion using samltools.com).</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
The customer is not using an IdP but a SAML assertion generator which is sent to the SP. The SAML response and assertion is valid but Shibboleth is returning a 500 for the /SAML2/POST instead of creating a session and redirecting the user to the service (lynda.com
in this case). </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
This was working with the previous version of our Shibboleth SP (2.3.1) but it's not working after we upgraded our SP to shibboleth version 2.6.4.1 (upgrade to 3.0.2 planned). </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
As mentioned, since the Assertion and Response are SAML-valid, I would expect an error in the logs if there is an issue with the coherence of the request. I'm looking for any suggestion to the investigate further this issue.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Our shibboleth SP DEBUG logs show no error or warning and ends with those 2 messages :</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<div style="margin:0px; font-size:16px; background-color:rgb(255,255,255)">2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [42]: signature verified against message issuer<br>
</div>
<div style="margin:0px; font-size:16px; background-color:rgb(255,255,255)">2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [42]: assertion satisfied bearer confirmation requirements</div>
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
I assume the next step is failing but I have no idea what exactly is failling.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span style="font-size:16px; background-color:rgb(255,255,255); display:inline!important">(Beginning of logs for this Entity ID, no SAML Request prior)</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span style="font-size:16px; background-color:rgb(255,255,255); display:inline!important"> </span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span>2018-09-27 10:56:04 DEBUG Shibboleth.Listener [42]: dispatching message (default/SAML2/POST)<br>
</span>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.MessageDecoder.SAML2POST [42]: validating input<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.MessageDecoder.SAML2POST [42]: decoded SAML message:<br>
</div>
<span><?xml version="1.0" encoding="UTF-8"?><saml2p:Response </span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span>[...output truncated see full content below...]</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
</saml2p:Response></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span>2018-09-27 10:56:04 DEBUG OpenSAML.MessageDecoder.SAML2 [42]: extracting issuer from SAML 2.0 protocol message<br>
</span>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.MessageDecoder.SAML2 [42]: message from (https://learnnsf.nsf.gov/GP-sp)<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.MessageDecoder.SAML2 [42]: searching metadata for message issuer...<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [42]: evaluating message flow policy (replay checking on, expiration 60)<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.StorageService [42]: inserted record (_1538070963159) in context (MessageFlow) with expiration (1538072823)<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [42]: validating signature profile<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.TrustEngine.ExplicitKey [42]: attempting to validate signature with the peer's credentials<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.TrustEngine.ExplicitKey [42]: signature validated with credential<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [42]: signature verified against message issuer<br>
</div>
<div>2018-09-27 10:56:04 DEBUG Shibboleth.SSO.SAML2 [42]: processing message against SAML 2.0 SSO profile<br>
</div>
<div>2018-09-27 10:56:04 DEBUG Shibboleth.SSO.SAML2 [42]: extracting issuer from SAML 2.0 assertion<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [42]: evaluating message flow policy (replay checking on, expiration 60)<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.StorageService [42]: inserted record (_1538070962807) in context (MessageFlow) with expiration (1538072822)<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [42]: validating signature profile<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.TrustEngine.ExplicitKey [42]: attempting to validate signature with the peer's credentials<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.TrustEngine.ExplicitKey [42]: signature validated with credential<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [42]: signature verified against message issuer<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [42]: assertion satisfied bearer confirmation requirements<br>
</div>
<span></span>(End of logs for this Entity ID) </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Here's the customer's metadata:</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" cacheDuration="PT1444927850S" entityID="https://learnnsf.nsf.gov/GP-sp"><br>
</span>
<div> <md:IDPSSODescriptor WantAuthnRequestsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><br>
</div>
<div> <md:KeyDescriptor use="signing"><br>
</div>
<div> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><br>
</div>
<div> <ds:X509Data><br>
</div>
<div> <ds:X509Certificate>MIIDrDCCApSgAwIBAgIEVhPszjANBgkqhkiG9w0BAQsFADCBlzEuMCwGCSqGSIb3DQEJARYfaG9z<br>
</div>
<div>dGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAk1EMREw<br>
</div>
<div>DwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZHUCBFVFMxGTAXBgNVBAMM<br>
</div>
<div>EGxlYXJubnNmLm5zZi5nb3YwHhcNMTUxMDA2MTU0NzA5WhcNNDUxMDA2MTU0NzA5WjCBlzEuMCwG<br>
</div>
<div>CSqGSIb3DQEJARYfaG9zdGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMx<br>
</div>
<div>CzAJBgNVBAgMAk1EMREwDwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZH<br>
</div>
<div>UCBFVFMxGTAXBgNVBAMMEGxlYXJubnNmLm5zZi5nb3YwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw<br>
</div>
<div>ggEKAoIBAQDNQjuStqTUlQVLoBDR5+kuVF7IC6swCg4RO4tc9ZGo0dqUqebc4vyLY72nuMvKQvQw<br>
</div>
<div>rR4SVlmmUPi2T03KFJ+P4pUJIk1erTIYk3wAgESYg01R84AraLKDlomln4aXKwvvDT4JRUMO4qpL<br>
</div>
<div>LzbAVaIX+wy1mBQtDXKP0Ugx4kY5RahHtUwbEBeog6Owbh1txGlV1+2mzk/m61hhcRVuxfnM/JOF<br>
</div>
<div>q/YXCBRJ38sq9XkfJ0+1C8vw4IvyIYuMQNQHRMzexL7G5BfUrRCc3SMUMjN1XrQClDWRhZMSAHp5<br>
</div>
<div>9GJBjKSdspCaWHj06qO7DzITsg+nWgKFGLpi6oo1XkuCXm0/AgMBAAEwDQYJKoZIhvcNAQELBQAD<br>
</div>
<div>ggEBAKnwT6lw4+kourGD8uowqAiuKX7jLccCm/Ip2rlKI7gp0P0x8bKeTNAJX+vmMMyij00/Htf0<br>
</div>
<div>DvirdiC43D6kzJoGm4/NYjQc94LJu+Pehu04rl6btn/fWZtFBR08uLdmHIFBHy6Us2tS5LWCnekt<br>
</div>
<div>TlBHTYWnj5yDkk7P+Fnla9uhN3YH52aAmdZwmUo8902TmPMhXuR9B34k/uaLGM2paQtCdACwtf8X<br>
</div>
<div>ANNJkLCUTyCgjV3vCuKCdEPwCsQwdmr1DtX3rs/A0jh6nbglcg+B7pJFYHkoBWCOYo6HXCzl1zSe<br>
</div>
<div>YfY96WszDLg2NcQm0SxWU/UyJhmZkLhK3J/B9x9vcd8=</ds:X509Certificate><br>
</div>
<div> </ds:X509Data><br>
</div>
<div> </ds:KeyInfo><br>
</div>
<div> </md:KeyDescriptor><br>
</div>
<div> <md:KeyDescriptor use="encryption"><br>
</div>
<div> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><br>
</div>
<div> <ds:X509Data><br>
</div>
<div> <ds:X509Certificate>MIIDrDCCApSgAwIBAgIEVhPszjANBgkqhkiG9w0BAQsFADCBlzEuMCwGCSqGSIb3DQEJARYfaG9z<br>
</div>
<div>dGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAk1EMREw<br>
</div>
<div>DwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZHUCBFVFMxGTAXBgNVBAMM<br>
</div>
<div>EGxlYXJubnNmLm5zZi5nb3YwHhcNMTUxMDA2MTU0NzA5WhcNNDUxMDA2MTU0NzA5WjCBlzEuMCwG<br>
</div>
<div>CSqGSIb3DQEJARYfaG9zdGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMx<br>
</div>
<div>CzAJBgNVBAgMAk1EMREwDwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZH<br>
</div>
<div>UCBFVFMxGTAXBgNVBAMMEGxlYXJubnNmLm5zZi5nb3YwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw<br>
</div>
<div>ggEKAoIBAQDNQjuStqTUlQVLoBDR5+kuVF7IC6swCg4RO4tc9ZGo0dqUqebc4vyLY72nuMvKQvQw<br>
</div>
<div>rR4SVlmmUPi2T03KFJ+P4pUJIk1erTIYk3wAgESYg01R84AraLKDlomln4aXKwvvDT4JRUMO4qpL<br>
</div>
<div>LzbAVaIX+wy1mBQtDXKP0Ugx4kY5RahHtUwbEBeog6Owbh1txGlV1+2mzk/m61hhcRVuxfnM/JOF<br>
</div>
<div>q/YXCBRJ38sq9XkfJ0+1C8vw4IvyIYuMQNQHRMzexL7G5BfUrRCc3SMUMjN1XrQClDWRhZMSAHp5<br>
</div>
<div>9GJBjKSdspCaWHj06qO7DzITsg+nWgKFGLpi6oo1XkuCXm0/AgMBAAEwDQYJKoZIhvcNAQELBQAD<br>
</div>
<div>ggEBAKnwT6lw4+kourGD8uowqAiuKX7jLccCm/Ip2rlKI7gp0P0x8bKeTNAJX+vmMMyij00/Htf0<br>
</div>
<div>DvirdiC43D6kzJoGm4/NYjQc94LJu+Pehu04rl6btn/fWZtFBR08uLdmHIFBHy6Us2tS5LWCnekt<br>
</div>
<div>TlBHTYWnj5yDkk7P+Fnla9uhN3YH52aAmdZwmUo8902TmPMhXuR9B34k/uaLGM2paQtCdACwtf8X<br>
</div>
<div>ANNJkLCUTyCgjV3vCuKCdEPwCsQwdmr1DtX3rs/A0jh6nbglcg+B7pJFYHkoBWCOYo6HXCzl1zSe<br>
</div>
<div>YfY96WszDLg2NcQm0SxWU/UyJhmZkLhK3J/B9x9vcd8=</ds:X509Certificate><br>
</div>
<div> </ds:X509Data><br>
</div>
<div> </ds:KeyInfo><br>
</div>
<div> </md:KeyDescriptor><br>
</div>
<div> <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat><br>
</div>
<div> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://learnnsf.nsf.gov/GP-sp" /><br>
</div>
<div> </md:IDPSSODescriptor><br>
</div>
<span> </md:EntityDescriptor></span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Here is the full SAML Response pretty printed and with PII obfuscatd:</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span><?xml version="1.0" encoding="UTF-8"?><br>
</span>
<div><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://shib.lynda.com/Shibboleth.sso/SAML2/POST" ID="_1538070963159" IssueInstant="2018-09-27T17:56:03.159Z" Version="2.0" xmlns:xs="http://www.w3.org/2001/XMLSchema"><br>
</div>
<div><saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">https://learnnsf.nsf.gov/GP-sp</saml2:Issuer><br>
</div>
<div><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><br>
</div>
<div> <ds:SignedInfo><br>
</div>
<div> <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><br>
</div>
<div> <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/><br>
</div>
<div> <ds:Reference URI="#_1538070963159"><br>
</div>
<div> <ds:Transforms><br>
</div>
<div> <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><br>
</div>
<div> <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"><br>
</div>
<div> <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/><br>
</div>
<div> </ds:Transform><br>
</div>
<div> </ds:Transforms><br>
</div>
<div> <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/><br>
</div>
<div> <ds:DigestValue>wqrjt3X51bLwPtjXghGl5UomlH0=</ds:DigestValue><br>
</div>
<div> </ds:Reference><br>
</div>
<div> </ds:SignedInfo><br>
</div>
<div> <ds:SignatureValue>DcAicMO1DwTwxr+gkjN6hi9CfnZCHIhTExDBrhZaHNf/ycxoKnRxF+7D9ZOOpslFFVguOnCKA+inlLVa4pf0j1tEsae4rsX7x5mW465YP+lcyNRY+OnadVvAK0rSjtKmYAPFKSTsEq4M0UN2QS43Oq43oEyhNy4jh8DaysR+foDUkmlpIuneTZ3HQtaOs6HwOOp6x9utKjqtyOQ8xDAvXHGUjM42bv60U9WXMuxfPh0TODMWncw4yFGAtxCMWO5BwRk53ngdJzKBvkodlbSNZwcmdXI6i6JCZqq4uVU2J1/QAj9CtWgJy/6RPiEJ2KaRBhvG5Bd4SavyYqa/MM9j6w==</ds:SignatureValue><br>
</div>
<div> <ds:KeyInfo><br>
</div>
<div> <ds:X509Data><br>
</div>
<div> <ds:X509Certificate>MIIDrDCCApSgAwIBAgIEVhPszjANBgkqhkiG9w0BAQsFADCBlzEuMCwGCSqGSIb3DQEJARYfaG9z<br>
</div>
<div>dGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAk1EMREw<br>
</div>
<div>DwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZHUCBFVFMxGTAXBgNVBAMM<br>
</div>
<div>EGxlYXJubnNmLm5zZi5nb3YwHhcNMTUxMDA2MTU0NzA5WhcNNDUxMDA2MTU0NzA5WjCBlzEuMCwG<br>
</div>
<div>CSqGSIb3DQEJARYfaG9zdGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMx<br>
</div>
<div>CzAJBgNVBAgMAk1EMREwDwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZH<br>
</div>
<div>UCBFVFMxGTAXBgNVBAMMEGxlYXJubnNmLm5zZi5nb3YwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw<br>
</div>
<div>ggEKAoIBAQDNQjuStqTUlQVLoBDR5+kuVF7IC6swCg4RO4tc9ZGo0dqUqebc4vyLY72nuMvKQvQw<br>
</div>
<div>rR4SVlmmUPi2T03KFJ+P4pUJIk1erTIYk3wAgESYg01R84AraLKDlomln4aXKwvvDT4JRUMO4qpL<br>
</div>
<div>LzbAVaIX+wy1mBQtDXKP0Ugx4kY5RahHtUwbEBeog6Owbh1txGlV1+2mzk/m61hhcRVuxfnM/JOF<br>
</div>
<div>q/YXCBRJ38sq9XkfJ0+1C8vw4IvyIYuMQNQHRMzexL7G5BfUrRCc3SMUMjN1XrQClDWRhZMSAHp5<br>
</div>
<div>9GJBjKSdspCaWHj06qO7DzITsg+nWgKFGLpi6oo1XkuCXm0/AgMBAAEwDQYJKoZIhvcNAQELBQAD<br>
</div>
<div>ggEBAKnwT6lw4+kourGD8uowqAiuKX7jLccCm/Ip2rlKI7gp0P0x8bKeTNAJX+vmMMyij00/Htf0<br>
</div>
<div>DvirdiC43D6kzJoGm4/NYjQc94LJu+Pehu04rl6btn/fWZtFBR08uLdmHIFBHy6Us2tS5LWCnekt<br>
</div>
<div>TlBHTYWnj5yDkk7P+Fnla9uhN3YH52aAmdZwmUo8902TmPMhXuR9B34k/uaLGM2paQtCdACwtf8X<br>
</div>
<div>ANNJkLCUTyCgjV3vCuKCdEPwCsQwdmr1DtX3rs/A0jh6nbglcg+B7pJFYHkoBWCOYo6HXCzl1zSe<br>
</div>
<div>YfY96WszDLg2NcQm0SxWU/UyJhmZkLhK3J/B9x9vcd8=</ds:X509Certificate><br>
</div>
<div> </ds:X509Data><br>
</div>
<div> </ds:KeyInfo><br>
</div>
<div></ds:Signature><br>
</div>
<div><saml2p:Status><br>
</div>
<div> <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/><br>
</div>
<div></saml2p:Status><br>
</div>
<div><saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_1538070962807" IssueInstant="2018-09-27T17:56:02.807Z" Version="2.0" xmlns:xs="http://www.w3.org/2001/XMLSchema"><br>
</div>
<div> <saml2:Issuer>https://learnnsf.nsf.gov/GP-sp</saml2:Issuer><br>
</div>
<div> <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><br>
</div>
<div> <ds:SignedInfo><br>
</div>
<div> <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><br>
</div>
<div> <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/><br>
</div>
<div> <ds:Reference URI="#_1538070962807"><br>
</div>
<div> <ds:Transforms><br>
</div>
<div> <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><br>
</div>
<div> <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"><br>
</div>
<div> <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/><br>
</div>
<div> </ds:Transform><br>
</div>
<div> </ds:Transforms><br>
</div>
<div> <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/><br>
</div>
<div> <ds:DigestValue>t44ltZbuNmwgYNMf+nVf9+Khnkk=</ds:DigestValue><br>
</div>
<div> </ds:Reference><br>
</div>
<div> </ds:SignedInfo><br>
</div>
<div> <ds:SignatureValue>mH2szsMpcnPoIUJLNKWY59kfn05Ygyn61xsnDN8Duw2+/gsNW0gFQPT9l5HhwgZZquoQqYwN/KGjRTUYPVfMtZVuCnWR6RyG0bq1sM5geb6JR2xsQTWQq5sLLFFj6gOsKjiD+1LHdKTQobuIk42bpknAn/cEy4WRzlIPJnmVE/ggQkqtjPpzr3iefpbUuNYO0piXaoejUWKjyf2DcI8PVrT74HYGVyaAoDzwHBUj5JgfoK5vIrWuJ+pl88LkleEs8kzUmr3wVkw5zmF7C3wk0wV8/WUuHYMVWYrwLnnnZtcXVriaVr0irVzhcwS0vgw7VgsEkxItZDDxeVsojN2r/w==</ds:SignatureValue><br>
</div>
<div> <ds:KeyInfo><br>
</div>
<div> <ds:X509Data><br>
</div>
<div> <ds:X509Certificate>MIIDrDCCApSgAwIBAgIEVhPszjANBgkqhkiG9w0BAQsFADCBlzEuMCwGCSqGSIb3DQEJARYfaG9z<br>
</div>
<div>dGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAk1EMREw<br>
</div>
<div>DwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZHUCBFVFMxGTAXBgNVBAMM<br>
</div>
<div>EGxlYXJubnNmLm5zZi5nb3YwHhcNMTUxMDA2MTU0NzA5WhcNNDUxMDA2MTU0NzA5WjCBlzEuMCwG<br>
</div>
<div>CSqGSIb3DQEJARYfaG9zdGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMx<br>
</div>
<div>CzAJBgNVBAgMAk1EMREwDwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZH<br>
</div>
<div>UCBFVFMxGTAXBgNVBAMMEGxlYXJubnNmLm5zZi5nb3YwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw<br>
</div>
<div>ggEKAoIBAQDNQjuStqTUlQVLoBDR5+kuVF7IC6swCg4RO4tc9ZGo0dqUqebc4vyLY72nuMvKQvQw<br>
</div>
<div>rR4SVlmmUPi2T03KFJ+P4pUJIk1erTIYk3wAgESYg01R84AraLKDlomln4aXKwvvDT4JRUMO4qpL<br>
</div>
<div>LzbAVaIX+wy1mBQtDXKP0Ugx4kY5RahHtUwbEBeog6Owbh1txGlV1+2mzk/m61hhcRVuxfnM/JOF<br>
</div>
<div>q/YXCBRJ38sq9XkfJ0+1C8vw4IvyIYuMQNQHRMzexL7G5BfUrRCc3SMUMjN1XrQClDWRhZMSAHp5<br>
</div>
<div>9GJBjKSdspCaWHj06qO7DzITsg+nWgKFGLpi6oo1XkuCXm0/AgMBAAEwDQYJKoZIhvcNAQELBQAD<br>
</div>
<div>ggEBAKnwT6lw4+kourGD8uowqAiuKX7jLccCm/Ip2rlKI7gp0P0x8bKeTNAJX+vmMMyij00/Htf0<br>
</div>
<div>DvirdiC43D6kzJoGm4/NYjQc94LJu+Pehu04rl6btn/fWZtFBR08uLdmHIFBHy6Us2tS5LWCnekt<br>
</div>
<div>TlBHTYWnj5yDkk7P+Fnla9uhN3YH52aAmdZwmUo8902TmPMhXuR9B34k/uaLGM2paQtCdACwtf8X<br>
</div>
<div>ANNJkLCUTyCgjV3vCuKCdEPwCsQwdmr1DtX3rs/A0jh6nbglcg+B7pJFYHkoBWCOYo6HXCzl1zSe<br>
</div>
<div>YfY96WszDLg2NcQm0SxWU/UyJhmZkLhK3J/B9x9vcd8=</ds:X509Certificate><br>
</div>
<div> </ds:X509Data><br>
</div>
<div> </ds:KeyInfo><br>
</div>
<div> </ds:Signature><br>
</div>
<div> <saml2:Subject><br>
</div>
<div> <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent">(OBFUSCATED)</saml2:NameID><br>
</div>
<div> <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><br>
</div>
<div> <saml2:SubjectConfirmationData NotOnOrAfter="2018-09-27T19:01:02.799Z" Recipient="https://shib.lynda.com/Shibboleth.sso/SAML2/POST"/><br>
</div>
<div> </saml2:SubjectConfirmation><br>
</div>
<div> </saml2:Subject><br>
</div>
<div> <saml2:Conditions><br>
</div>
<div> <saml2:OneTimeUse/><br>
</div>
<div> <saml2:AudienceRestriction><br>
</div>
<div> <saml2:Audience>https://shib.lynda.com/shibboleth-sp</saml2:Audience><br>
</div>
<div> </saml2:AudienceRestriction><br>
</div>
<div> </saml2:Conditions><br>
</div>
<div> <saml2:AuthnStatement AuthnInstant="2018-09-27T18:56:02.799Z" SessionNotOnOrAfter="2018-09-27T19:11:02.799Z"><br>
</div>
<div> <saml2:AuthnContext><br>
</div>
<div> <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</saml2:AuthnContextClassRef><br>
</div>
<div> </saml2:AuthnContext><br>
</div>
<div> </saml2:AuthnStatement><br>
</div>
<div> <saml2:AttributeStatement><br>
</div>
<div> <saml2:Attribute Name="mail"><br>
</div>
<div> <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string"/><br>
</div>
<div> </saml2:Attribute><br>
</div>
<div> <saml2:Attribute Name="sn"><br>
</div>
<div> <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">(OBFUSCATED)</saml2:AttributeValue><br>
</div>
<div> </saml2:Attribute><br>
</div>
<div> <saml2:Attribute Name="givenName"><br>
</div>
<div> <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">(OBFUSCATED)</saml2:AttributeValue><br>
</div>
<div> </saml2:Attribute><br>
</div>
<div> </saml2:AttributeStatement><br>
</div>
<div></saml2:Assertion><br>
</div>
<div></saml2p:Response><br>
</div>
<span></span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Thank you</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Thomas</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div id="x_signature">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p style="margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px">
-- </p>
<p style="margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px">
Thomas Blanchard</p>
<p style="margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px">
LinkedIn Learning & Lynda SRE</p>
</div>
</div>
</div>
</body>
</html>