<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<pre>On 10/1/18, 8:46 PM, "users on behalf of Cantor, Scott" <<a href="https://shibboleth.net/mailman/listinfo/users">users-bounces at shibboleth.net</a> on behalf of <a href="https://shibboleth.net/mailman/listinfo/users">cantor.2 at osu.edu</a>> wrote:
><i> The AuthnInstant is not going to matter to the SP unless it's told to look at it, so that wasn't the issue
</i>
Unless it was in the future. I forgot that it checked for that. I assume it was forward an hour. If it's future-dated, it won't accept it, and it tracks that as a message and throws an exception with that error message in it.
It just didn't log it where you looked, but most of those error paths are rare and have been getting plugged gradually if they're not getting logged on that side of the system. A few are still probably leaking out and they would show up in native.log / Event Log and in the browser unless the web server is broken (i.e. IIS) and deliberately configured to hide the errors.
But yes, that will fail the login as it turns out, my mistake initially.
-- Scott</pre>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">To wrap up this issue: the AuthnInstant was indeed 1h in the future, after fixing this and having it match IssueInstant, the Assertion is now accepted and
customers can log in.</span><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;"><br>
</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="color: rgb(0, 0, 0); font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt;">
<div style=" margin: 0px">Thank you Scott for your help !</div>
</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="signature">
<div id="divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p style="margin-top: 0px; margin-bottom: 0px;">-- </p>
<p style="margin-top: 0px; margin-bottom: 0px;">Thomas Blanchard</p>
<p style="margin-top: 0px; margin-bottom: 0px;">LinkedIn Learning & Lynda SRE</p>
</div>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Thomas Blanchard<br>
<b>Sent:</b> Monday, October 1, 2018 20:36<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Re: Shibboleth SP 500 after processing valid SAML response and assertion</font>
<div> </div>
</div>
<meta content="text/html; charset=us-ascii">
<style type="text/css" style="display:none">
<!--
p
{margin-top:0;
margin-bottom:0}
-->
</style>
<div dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<b style="font-family:"Times New Roman"; font-size:medium">Cantor, Scott</b><span style="font-family:"Times New Roman"; font-size:medium; background-color:rgb(255,255,255); display:inline!important"><span> </span></span><a href="mailto:users%40shibboleth.net?Subject=Re:%20Re%3A%20Shibboleth%20SP%20500%20after%20processing%20valid%20SAML%20response%20and%0A%20assertion&In-Reply-To=%3C6C0AA522-4850-4783-A999-27F22C6BBA32%40osu.edu%3E" title="Shibboleth SP 500 after processing valid SAML response and assertion" style="font-family:"Times New Roman"; font-size:medium">cantor.2
at osu.edu<span> </span></a><br style="font-family:"Times New Roman"; font-size:medium">
<i style="font-family:"Times New Roman"; font-size:medium">Mon Oct 1 14:16:39 EDT 2018</i><br>
<pre>><i> As mentioned, since the Assertion and Response are SAML-valid, I would expect an error in the logs if there is an issue
</i>><i> with the coherence of the request. I'm looking for any suggestion to the investigate further this issue.
</i>
I would be very surprised if nothing is logged but be that as it may I think the problem is the OneTimeUse Condition in there, which is not processed/accepted by the default policy rules the SP ships with.
-- Scott
</pre>
Thank you Scott, after the customer changed the time on its server for testing purposes, we figured out that their
<span style="font-size:16px; background-color:rgb(255,255,255); display:inline!important">
AuthnInstant<span> in the </span></span>AuthnStatement had 1h difference with the Response and Assertion's IssueInstant.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
It looks like in this case, the SP did not emit any error or warning, but simply dropped the assertion. Is this expected behavior ? Can I assume that when no error or warning is in the logs, then the issue is in the coherence of the response ? Or is it such
an edge case that this is not dealt with in the logs ?</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Here are the logs' timestamps for reference: </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
2018-10-01 11:45:43-0700 DEBUG OpenSAML.MessageDecoder.SAML2POST [10]: decoded SAML message:<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<div>saml2p:Response IssueInstant="2018-10-01T18:43:57.389Z"<br>
</div>
<div>saml2:Assertion IssueInstant="2018-10-01T18:43:51.928Z" <br>
</div>
<div>saml2:SubjectConfirmationData NotOnOrAfter="2018-10-01T19:48:51.928Z"<br>
</div>
<div>AuthnStatement AuthnInstant="2018-10-01T19:43:51.928Z" SessionNotOnOrAfter="2018-10-01T19:58:51.928Z"><br>
</div>
<div><br>
</div>
<div>We managed to test a successful login by fiddling with test servers' time to confirm this is the issue.</div>
<div><br>
</div>
<span></span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Thomas<br>
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div id="x_signature">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p style="margin-top:0px; margin-bottom:0px">-- </p>
<p style="margin-top:0px; margin-bottom:0px">Thomas Blanchard</p>
<div style="margin-top:0px; margin-bottom:0px"><span>LinkedIn Learning & Lynda SRE</span><span></span></div>
</div>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> Thomas Blanchard<br>
<b>Sent:</b> Monday, October 1, 2018 13:58<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Shibboleth SP 500 after processing valid SAML response and assertion</font>
<div> </div>
</div>
<meta content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none">
<!--
p
{margin-top:0;
margin-bottom:0}
-->
</style>
<div dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Hello everyone, </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
I'm having a really troubling issue with a customer getting 500 during the SAML Response processing after passing a valid Response and Assertion (I validated both the whole response and the assertion using samltools.com).</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
The customer is not using an IdP but a SAML assertion generator which is sent to the SP. The SAML response and assertion is valid but Shibboleth is returning a 500 for the /SAML2/POST instead of creating a session and redirecting the user to the service (lynda.com
in this case). </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
This was working with the previous version of our Shibboleth SP (2.3.1) but it's not working after we upgraded our SP to shibboleth version 2.6.4.1 (upgrade to 3.0.2 planned). </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
As mentioned, since the Assertion and Response are SAML-valid, I would expect an error in the logs if there is an issue with the coherence of the request. I'm looking for any suggestion to the investigate further this issue.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Our shibboleth SP DEBUG logs show no error or warning and ends with those 2 messages :</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<div style="margin:0px; font-size:16px; background-color:rgb(255,255,255)">2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [42]: signature verified against message issuer<br>
</div>
<div style="margin:0px; font-size:16px; background-color:rgb(255,255,255)">2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [42]: assertion satisfied bearer confirmation requirements</div>
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
I assume the next step is failing but I have no idea what exactly is failling.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span style="font-size:16px; background-color:rgb(255,255,255); display:inline!important">(Beginning of logs for this Entity ID, no SAML Request prior)</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span style="font-size:16px; background-color:rgb(255,255,255); display:inline!important"> </span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span>2018-09-27 10:56:04 DEBUG Shibboleth.Listener [42]: dispatching message (default/SAML2/POST)<br>
</span>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.MessageDecoder.SAML2POST [42]: validating input<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.MessageDecoder.SAML2POST [42]: decoded SAML message:<br>
</div>
<span><?xml version="1.0" encoding="UTF-8"?><saml2p:Response </span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span>[...output truncated see full content below...]</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
</saml2p:Response></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span>2018-09-27 10:56:04 DEBUG OpenSAML.MessageDecoder.SAML2 [42]: extracting issuer from SAML 2.0 protocol message<br>
</span>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.MessageDecoder.SAML2 [42]: message from (https://learnnsf.nsf.gov/GP-sp)<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.MessageDecoder.SAML2 [42]: searching metadata for message issuer...<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [42]: evaluating message flow policy (replay checking on, expiration 60)<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.StorageService [42]: inserted record (_1538070963159) in context (MessageFlow) with expiration (1538072823)<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [42]: validating signature profile<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.TrustEngine.ExplicitKey [42]: attempting to validate signature with the peer's credentials<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.TrustEngine.ExplicitKey [42]: signature validated with credential<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [42]: signature verified against message issuer<br>
</div>
<div>2018-09-27 10:56:04 DEBUG Shibboleth.SSO.SAML2 [42]: processing message against SAML 2.0 SSO profile<br>
</div>
<div>2018-09-27 10:56:04 DEBUG Shibboleth.SSO.SAML2 [42]: extracting issuer from SAML 2.0 assertion<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [42]: evaluating message flow policy (replay checking on, expiration 60)<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.StorageService [42]: inserted record (_1538070962807) in context (MessageFlow) with expiration (1538072822)<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [42]: validating signature profile<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.TrustEngine.ExplicitKey [42]: attempting to validate signature with the peer's credentials<br>
</div>
<div>2018-09-27 10:56:04 DEBUG XMLTooling.TrustEngine.ExplicitKey [42]: signature validated with credential<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [42]: signature verified against message issuer<br>
</div>
<div>2018-09-27 10:56:04 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [42]: assertion satisfied bearer confirmation requirements<br>
</div>
<span></span>(End of logs for this Entity ID) </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Here's the customer's metadata:</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" cacheDuration="PT1444927850S" entityID="https://learnnsf.nsf.gov/GP-sp"><br>
</span>
<div> <md:IDPSSODescriptor WantAuthnRequestsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><br>
</div>
<div> <md:KeyDescriptor use="signing"><br>
</div>
<div> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><br>
</div>
<div> <ds:X509Data><br>
</div>
<div> <ds:X509Certificate>MIIDrDCCApSgAwIBAgIEVhPszjANBgkqhkiG9w0BAQsFADCBlzEuMCwGCSqGSIb3DQEJARYfaG9z<br>
</div>
<div>dGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAk1EMREw<br>
</div>
<div>DwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZHUCBFVFMxGTAXBgNVBAMM<br>
</div>
<div>EGxlYXJubnNmLm5zZi5nb3YwHhcNMTUxMDA2MTU0NzA5WhcNNDUxMDA2MTU0NzA5WjCBlzEuMCwG<br>
</div>
<div>CSqGSIb3DQEJARYfaG9zdGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMx<br>
</div>
<div>CzAJBgNVBAgMAk1EMREwDwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZH<br>
</div>
<div>UCBFVFMxGTAXBgNVBAMMEGxlYXJubnNmLm5zZi5nb3YwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw<br>
</div>
<div>ggEKAoIBAQDNQjuStqTUlQVLoBDR5+kuVF7IC6swCg4RO4tc9ZGo0dqUqebc4vyLY72nuMvKQvQw<br>
</div>
<div>rR4SVlmmUPi2T03KFJ+P4pUJIk1erTIYk3wAgESYg01R84AraLKDlomln4aXKwvvDT4JRUMO4qpL<br>
</div>
<div>LzbAVaIX+wy1mBQtDXKP0Ugx4kY5RahHtUwbEBeog6Owbh1txGlV1+2mzk/m61hhcRVuxfnM/JOF<br>
</div>
<div>q/YXCBRJ38sq9XkfJ0+1C8vw4IvyIYuMQNQHRMzexL7G5BfUrRCc3SMUMjN1XrQClDWRhZMSAHp5<br>
</div>
<div>9GJBjKSdspCaWHj06qO7DzITsg+nWgKFGLpi6oo1XkuCXm0/AgMBAAEwDQYJKoZIhvcNAQELBQAD<br>
</div>
<div>ggEBAKnwT6lw4+kourGD8uowqAiuKX7jLccCm/Ip2rlKI7gp0P0x8bKeTNAJX+vmMMyij00/Htf0<br>
</div>
<div>DvirdiC43D6kzJoGm4/NYjQc94LJu+Pehu04rl6btn/fWZtFBR08uLdmHIFBHy6Us2tS5LWCnekt<br>
</div>
<div>TlBHTYWnj5yDkk7P+Fnla9uhN3YH52aAmdZwmUo8902TmPMhXuR9B34k/uaLGM2paQtCdACwtf8X<br>
</div>
<div>ANNJkLCUTyCgjV3vCuKCdEPwCsQwdmr1DtX3rs/A0jh6nbglcg+B7pJFYHkoBWCOYo6HXCzl1zSe<br>
</div>
<div>YfY96WszDLg2NcQm0SxWU/UyJhmZkLhK3J/B9x9vcd8=</ds:X509Certificate><br>
</div>
<div> </ds:X509Data><br>
</div>
<div> </ds:KeyInfo><br>
</div>
<div> </md:KeyDescriptor><br>
</div>
<div> <md:KeyDescriptor use="encryption"><br>
</div>
<div> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><br>
</div>
<div> <ds:X509Data><br>
</div>
<div> <ds:X509Certificate>MIIDrDCCApSgAwIBAgIEVhPszjANBgkqhkiG9w0BAQsFADCBlzEuMCwGCSqGSIb3DQEJARYfaG9z<br>
</div>
<div>dGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAk1EMREw<br>
</div>
<div>DwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZHUCBFVFMxGTAXBgNVBAMM<br>
</div>
<div>EGxlYXJubnNmLm5zZi5nb3YwHhcNMTUxMDA2MTU0NzA5WhcNNDUxMDA2MTU0NzA5WjCBlzEuMCwG<br>
</div>
<div>CSqGSIb3DQEJARYfaG9zdGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMx<br>
</div>
<div>CzAJBgNVBAgMAk1EMREwDwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZH<br>
</div>
<div>UCBFVFMxGTAXBgNVBAMMEGxlYXJubnNmLm5zZi5nb3YwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw<br>
</div>
<div>ggEKAoIBAQDNQjuStqTUlQVLoBDR5+kuVF7IC6swCg4RO4tc9ZGo0dqUqebc4vyLY72nuMvKQvQw<br>
</div>
<div>rR4SVlmmUPi2T03KFJ+P4pUJIk1erTIYk3wAgESYg01R84AraLKDlomln4aXKwvvDT4JRUMO4qpL<br>
</div>
<div>LzbAVaIX+wy1mBQtDXKP0Ugx4kY5RahHtUwbEBeog6Owbh1txGlV1+2mzk/m61hhcRVuxfnM/JOF<br>
</div>
<div>q/YXCBRJ38sq9XkfJ0+1C8vw4IvyIYuMQNQHRMzexL7G5BfUrRCc3SMUMjN1XrQClDWRhZMSAHp5<br>
</div>
<div>9GJBjKSdspCaWHj06qO7DzITsg+nWgKFGLpi6oo1XkuCXm0/AgMBAAEwDQYJKoZIhvcNAQELBQAD<br>
</div>
<div>ggEBAKnwT6lw4+kourGD8uowqAiuKX7jLccCm/Ip2rlKI7gp0P0x8bKeTNAJX+vmMMyij00/Htf0<br>
</div>
<div>DvirdiC43D6kzJoGm4/NYjQc94LJu+Pehu04rl6btn/fWZtFBR08uLdmHIFBHy6Us2tS5LWCnekt<br>
</div>
<div>TlBHTYWnj5yDkk7P+Fnla9uhN3YH52aAmdZwmUo8902TmPMhXuR9B34k/uaLGM2paQtCdACwtf8X<br>
</div>
<div>ANNJkLCUTyCgjV3vCuKCdEPwCsQwdmr1DtX3rs/A0jh6nbglcg+B7pJFYHkoBWCOYo6HXCzl1zSe<br>
</div>
<div>YfY96WszDLg2NcQm0SxWU/UyJhmZkLhK3J/B9x9vcd8=</ds:X509Certificate><br>
</div>
<div> </ds:X509Data><br>
</div>
<div> </ds:KeyInfo><br>
</div>
<div> </md:KeyDescriptor><br>
</div>
<div> <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat><br>
</div>
<div> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://learnnsf.nsf.gov/GP-sp" /><br>
</div>
<div> </md:IDPSSODescriptor><br>
</div>
<span> </md:EntityDescriptor></span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Here is the full SAML Response pretty printed and with PII obfuscatd:</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<span><?xml version="1.0" encoding="UTF-8"?><br>
</span>
<div><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://shib.lynda.com/Shibboleth.sso/SAML2/POST" ID="_1538070963159" IssueInstant="2018-09-27T17:56:03.159Z" Version="2.0" xmlns:xs="http://www.w3.org/2001/XMLSchema"><br>
</div>
<div><saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">https://learnnsf.nsf.gov/GP-sp</saml2:Issuer><br>
</div>
<div><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><br>
</div>
<div> <ds:SignedInfo><br>
</div>
<div> <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><br>
</div>
<div> <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/><br>
</div>
<div> <ds:Reference URI="#_1538070963159"><br>
</div>
<div> <ds:Transforms><br>
</div>
<div> <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><br>
</div>
<div> <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"><br>
</div>
<div> <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/><br>
</div>
<div> </ds:Transform><br>
</div>
<div> </ds:Transforms><br>
</div>
<div> <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/><br>
</div>
<div> <ds:DigestValue>wqrjt3X51bLwPtjXghGl5UomlH0=</ds:DigestValue><br>
</div>
<div> </ds:Reference><br>
</div>
<div> </ds:SignedInfo><br>
</div>
<div> <ds:SignatureValue>DcAicMO1DwTwxr+gkjN6hi9CfnZCHIhTExDBrhZaHNf/ycxoKnRxF+7D9ZOOpslFFVguOnCKA+inlLVa4pf0j1tEsae4rsX7x5mW465YP+lcyNRY+OnadVvAK0rSjtKmYAPFKSTsEq4M0UN2QS43Oq43oEyhNy4jh8DaysR+foDUkmlpIuneTZ3HQtaOs6HwOOp6x9utKjqtyOQ8xDAvXHGUjM42bv60U9WXMuxfPh0TODMWncw4yFGAtxCMWO5BwRk53ngdJzKBvkodlbSNZwcmdXI6i6JCZqq4uVU2J1/QAj9CtWgJy/6RPiEJ2KaRBhvG5Bd4SavyYqa/MM9j6w==</ds:SignatureValue><br>
</div>
<div> <ds:KeyInfo><br>
</div>
<div> <ds:X509Data><br>
</div>
<div> <ds:X509Certificate>MIIDrDCCApSgAwIBAgIEVhPszjANBgkqhkiG9w0BAQsFADCBlzEuMCwGCSqGSIb3DQEJARYfaG9z<br>
</div>
<div>dGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAk1EMREw<br>
</div>
<div>DwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZHUCBFVFMxGTAXBgNVBAMM<br>
</div>
<div>EGxlYXJubnNmLm5zZi5nb3YwHhcNMTUxMDA2MTU0NzA5WhcNNDUxMDA2MTU0NzA5WjCBlzEuMCwG<br>
</div>
<div>CSqGSIb3DQEJARYfaG9zdGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMx<br>
</div>
<div>CzAJBgNVBAgMAk1EMREwDwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZH<br>
</div>
<div>UCBFVFMxGTAXBgNVBAMMEGxlYXJubnNmLm5zZi5nb3YwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw<br>
</div>
<div>ggEKAoIBAQDNQjuStqTUlQVLoBDR5+kuVF7IC6swCg4RO4tc9ZGo0dqUqebc4vyLY72nuMvKQvQw<br>
</div>
<div>rR4SVlmmUPi2T03KFJ+P4pUJIk1erTIYk3wAgESYg01R84AraLKDlomln4aXKwvvDT4JRUMO4qpL<br>
</div>
<div>LzbAVaIX+wy1mBQtDXKP0Ugx4kY5RahHtUwbEBeog6Owbh1txGlV1+2mzk/m61hhcRVuxfnM/JOF<br>
</div>
<div>q/YXCBRJ38sq9XkfJ0+1C8vw4IvyIYuMQNQHRMzexL7G5BfUrRCc3SMUMjN1XrQClDWRhZMSAHp5<br>
</div>
<div>9GJBjKSdspCaWHj06qO7DzITsg+nWgKFGLpi6oo1XkuCXm0/AgMBAAEwDQYJKoZIhvcNAQELBQAD<br>
</div>
<div>ggEBAKnwT6lw4+kourGD8uowqAiuKX7jLccCm/Ip2rlKI7gp0P0x8bKeTNAJX+vmMMyij00/Htf0<br>
</div>
<div>DvirdiC43D6kzJoGm4/NYjQc94LJu+Pehu04rl6btn/fWZtFBR08uLdmHIFBHy6Us2tS5LWCnekt<br>
</div>
<div>TlBHTYWnj5yDkk7P+Fnla9uhN3YH52aAmdZwmUo8902TmPMhXuR9B34k/uaLGM2paQtCdACwtf8X<br>
</div>
<div>ANNJkLCUTyCgjV3vCuKCdEPwCsQwdmr1DtX3rs/A0jh6nbglcg+B7pJFYHkoBWCOYo6HXCzl1zSe<br>
</div>
<div>YfY96WszDLg2NcQm0SxWU/UyJhmZkLhK3J/B9x9vcd8=</ds:X509Certificate><br>
</div>
<div> </ds:X509Data><br>
</div>
<div> </ds:KeyInfo><br>
</div>
<div></ds:Signature><br>
</div>
<div><saml2p:Status><br>
</div>
<div> <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/><br>
</div>
<div></saml2p:Status><br>
</div>
<div><saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_1538070962807" IssueInstant="2018-09-27T17:56:02.807Z" Version="2.0" xmlns:xs="http://www.w3.org/2001/XMLSchema"><br>
</div>
<div> <saml2:Issuer>https://learnnsf.nsf.gov/GP-sp</saml2:Issuer><br>
</div>
<div> <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><br>
</div>
<div> <ds:SignedInfo><br>
</div>
<div> <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><br>
</div>
<div> <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/><br>
</div>
<div> <ds:Reference URI="#_1538070962807"><br>
</div>
<div> <ds:Transforms><br>
</div>
<div> <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><br>
</div>
<div> <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"><br>
</div>
<div> <ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/><br>
</div>
<div> </ds:Transform><br>
</div>
<div> </ds:Transforms><br>
</div>
<div> <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/><br>
</div>
<div> <ds:DigestValue>t44ltZbuNmwgYNMf+nVf9+Khnkk=</ds:DigestValue><br>
</div>
<div> </ds:Reference><br>
</div>
<div> </ds:SignedInfo><br>
</div>
<div> <ds:SignatureValue>mH2szsMpcnPoIUJLNKWY59kfn05Ygyn61xsnDN8Duw2+/gsNW0gFQPT9l5HhwgZZquoQqYwN/KGjRTUYPVfMtZVuCnWR6RyG0bq1sM5geb6JR2xsQTWQq5sLLFFj6gOsKjiD+1LHdKTQobuIk42bpknAn/cEy4WRzlIPJnmVE/ggQkqtjPpzr3iefpbUuNYO0piXaoejUWKjyf2DcI8PVrT74HYGVyaAoDzwHBUj5JgfoK5vIrWuJ+pl88LkleEs8kzUmr3wVkw5zmF7C3wk0wV8/WUuHYMVWYrwLnnnZtcXVriaVr0irVzhcwS0vgw7VgsEkxItZDDxeVsojN2r/w==</ds:SignatureValue><br>
</div>
<div> <ds:KeyInfo><br>
</div>
<div> <ds:X509Data><br>
</div>
<div> <ds:X509Certificate>MIIDrDCCApSgAwIBAgIEVhPszjANBgkqhkiG9w0BAQsFADCBlzEuMCwGCSqGSIb3DQEJARYfaG9z<br>
</div>
<div>dGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAk1EMREw<br>
</div>
<div>DwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZHUCBFVFMxGTAXBgNVBAMM<br>
</div>
<div>EGxlYXJubnNmLm5zZi5nb3YwHhcNMTUxMDA2MTU0NzA5WhcNNDUxMDA2MTU0NzA5WjCBlzEuMCwG<br>
</div>
<div>CSqGSIb3DQEJARYfaG9zdGluZ3N1cHBvcnRAZ3BzdHJhdGVnaWVzLmNvbTELMAkGA1UEBhMCVVMx<br>
</div>
<div>CzAJBgNVBAgMAk1EMREwDwYDVQQHDAhDb2x1bWJpYTEMMAoGA1UECgwDTlNGMQ8wDQYDVQQLDAZH<br>
</div>
<div>UCBFVFMxGTAXBgNVBAMMEGxlYXJubnNmLm5zZi5nb3YwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw<br>
</div>
<div>ggEKAoIBAQDNQjuStqTUlQVLoBDR5+kuVF7IC6swCg4RO4tc9ZGo0dqUqebc4vyLY72nuMvKQvQw<br>
</div>
<div>rR4SVlmmUPi2T03KFJ+P4pUJIk1erTIYk3wAgESYg01R84AraLKDlomln4aXKwvvDT4JRUMO4qpL<br>
</div>
<div>LzbAVaIX+wy1mBQtDXKP0Ugx4kY5RahHtUwbEBeog6Owbh1txGlV1+2mzk/m61hhcRVuxfnM/JOF<br>
</div>
<div>q/YXCBRJ38sq9XkfJ0+1C8vw4IvyIYuMQNQHRMzexL7G5BfUrRCc3SMUMjN1XrQClDWRhZMSAHp5<br>
</div>
<div>9GJBjKSdspCaWHj06qO7DzITsg+nWgKFGLpi6oo1XkuCXm0/AgMBAAEwDQYJKoZIhvcNAQELBQAD<br>
</div>
<div>ggEBAKnwT6lw4+kourGD8uowqAiuKX7jLccCm/Ip2rlKI7gp0P0x8bKeTNAJX+vmMMyij00/Htf0<br>
</div>
<div>DvirdiC43D6kzJoGm4/NYjQc94LJu+Pehu04rl6btn/fWZtFBR08uLdmHIFBHy6Us2tS5LWCnekt<br>
</div>
<div>TlBHTYWnj5yDkk7P+Fnla9uhN3YH52aAmdZwmUo8902TmPMhXuR9B34k/uaLGM2paQtCdACwtf8X<br>
</div>
<div>ANNJkLCUTyCgjV3vCuKCdEPwCsQwdmr1DtX3rs/A0jh6nbglcg+B7pJFYHkoBWCOYo6HXCzl1zSe<br>
</div>
<div>YfY96WszDLg2NcQm0SxWU/UyJhmZkLhK3J/B9x9vcd8=</ds:X509Certificate><br>
</div>
<div> </ds:X509Data><br>
</div>
<div> </ds:KeyInfo><br>
</div>
<div> </ds:Signature><br>
</div>
<div> <saml2:Subject><br>
</div>
<div> <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent">(OBFUSCATED)</saml2:NameID><br>
</div>
<div> <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><br>
</div>
<div> <saml2:SubjectConfirmationData NotOnOrAfter="2018-09-27T19:01:02.799Z" Recipient="https://shib.lynda.com/Shibboleth.sso/SAML2/POST"/><br>
</div>
<div> </saml2:SubjectConfirmation><br>
</div>
<div> </saml2:Subject><br>
</div>
<div> <saml2:Conditions><br>
</div>
<div> <saml2:OneTimeUse/><br>
</div>
<div> <saml2:AudienceRestriction><br>
</div>
<div> <saml2:Audience>https://shib.lynda.com/shibboleth-sp</saml2:Audience><br>
</div>
<div> </saml2:AudienceRestriction><br>
</div>
<div> </saml2:Conditions><br>
</div>
<div> <saml2:AuthnStatement AuthnInstant="2018-09-27T18:56:02.799Z" SessionNotOnOrAfter="2018-09-27T19:11:02.799Z"><br>
</div>
<div> <saml2:AuthnContext><br>
</div>
<div> <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</saml2:AuthnContextClassRef><br>
</div>
<div> </saml2:AuthnContext><br>
</div>
<div> </saml2:AuthnStatement><br>
</div>
<div> <saml2:AttributeStatement><br>
</div>
<div> <saml2:Attribute Name="mail"><br>
</div>
<div> <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string"/><br>
</div>
<div> </saml2:Attribute><br>
</div>
<div> <saml2:Attribute Name="sn"><br>
</div>
<div> <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">(OBFUSCATED)</saml2:AttributeValue><br>
</div>
<div> </saml2:Attribute><br>
</div>
<div> <saml2:Attribute Name="givenName"><br>
</div>
<div> <saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">(OBFUSCATED)</saml2:AttributeValue><br>
</div>
<div> </saml2:Attribute><br>
</div>
<div> </saml2:AttributeStatement><br>
</div>
<div></saml2:Assertion><br>
</div>
<div></saml2p:Response><br>
</div>
<span></span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Thank you</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Thomas</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div id="x_x_signature">
<div id="x_x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p style="margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px">
-- </p>
<p style="margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px">
Thomas Blanchard</p>
<p style="margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px; margin-top:0px; margin-bottom:0px">
LinkedIn Learning & Lynda SRE</p>
</div>
</div>
</div>
</div>
</body>
</html>