<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Texto de globo Car";
        margin:0cm;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
span.EstiloCorreo17
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.TextodegloboCar
        {mso-style-name:"Texto de globo Car";
        mso-style-priority:99;
        mso-style-link:"Texto de globo";
        font-family:"Tahoma","sans-serif";
        mso-fareast-language:ES;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:70.85pt 3.0cm 70.85pt 3.0cm;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="ES" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Thanks a lot Greg!<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">So maybe on our application there is one of this vanity URLs to access a Google Application…<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">I’m going to ask around, maybe another team used one of them.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Regards<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" width="767" style="width:460.35pt;margin-left:5.4pt;border-collapse:collapse">
<tbody>
<tr style="height:62.55pt">
<td width="767" colspan="2" valign="top" style="width:460.35pt;border:none;border-right:solid white 1.0pt;padding:0cm 0cm 0cm 0cm;height:62.55pt">
<p class="MsoNormal"><b><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#0099D4;mso-fareast-language:EN-US">Miguel Salinas Vivancos</span></b><b><span lang="EN-US" style="font-size:10.0pt;font-family:"Calibri","sans-serif";color:#0099D4;mso-fareast-language:EN-US"><o:p></o:p></span></b></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US">Identity Management Integrator
<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:6.0pt;margin-right:0cm;margin-bottom:6.0pt;margin-left:0cm;text-align:justify;line-height:120%">
<span lang="EN-US" style="font-size:11.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US">Tel.: +34 639 198 154</span><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US">
</span><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#0099D4;mso-fareast-language:EN-US">–
</span><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US">mail:msalinas@bcn.sia.es</span><b><span lang="EN-US" style="font-size:11.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US"><o:p></o:p></span></b></p>
</td>
</tr>
<tr style="height:2.8pt">
<td width="118" valign="top" style="width:70.9pt;border:none;border-right:solid #0099D4 1.0pt;padding:0cm 0cm 0cm 0cm;height:2.8pt">
<p class="MsoNormal" style="mso-margin-top-alt:6.0pt;margin-right:0cm;margin-bottom:6.0pt;margin-left:0cm;text-align:justify;line-height:120%">
<b><span style="font-size:11.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040"><img width="100" height="56" id="Imagen_x0020_1" src="cid:image001.png@01D5627C.93121440" alt="cid:image001.png@01D52CD1.D29CDC20"></span></b><b><span style="font-size:11.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US"><o:p></o:p></span></b></p>
</td>
<td width="649" style="width:389.45pt;border:none;border-right:solid white 1.0pt;padding:0cm 0cm 0cm 0cm;height:2.8pt">
<p class="MsoNormal"><b><span style="font-size:9.0pt;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US">Grupo SIA</span></b><b><span style="font-size:9.0pt;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US"><o:p></o:p></span></b></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US">Citypark, Edificio Atenas, Ctra.
</span><span lang="EN-US" style="font-size:9.0pt;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US">Hospitalet 147. 08940 Cornellá de Llobregat – Barcelona<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:6.0pt;margin-right:0cm;margin-bottom:6.0pt;margin-left:0cm;text-align:justify;line-height:120%">
<span style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US"><a href="http://www.sia.es/"><span lang="EN-US" style="color:#404040">www.sia.es</span></a></span><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US"> 
</span><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#0099D4;mso-fareast-language:EN-US">-
</span><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US">Twitter:</span><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#0099D4;mso-fareast-language:EN-US">
</span><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US">@SIA_es 
</span><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#0099D4;mso-fareast-language:EN-US">-
</span><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US">LinkedIn: Grupo SIA</span><b><span lang="EN-US" style="font-size:9.0pt;line-height:120%;font-family:"Calibri","sans-serif";color:#404040;mso-fareast-language:EN-US"><o:p></o:p></span></b></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">De:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> users [mailto:users-bounces@shibboleth.net]
<b>En nombre de </b>Greg Haverkamp<br>
<b>Enviado el:</b> martes, 3 de septiembre de 2019 17:15<br>
<b>Para:</b> Shib Users<br>
<b>Asunto:</b> Re: Massive authentications from SP GoogleApps<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<p class="MsoNormal">On Tue, Sep 3, 2019 at 7:18 AM Miguel Salinas Vivancos <<a href="mailto:msalinas@bcn.sia.es">msalinas@bcn.sia.es</a>> wrote:<o:p></o:p></p>
</div>
<div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm">
<p class="MsoNormal">Hi Steve, thank you for your answer.<br>
If the hypothesis is a SAML Response rejected by the SP, then it will only happen with specific Google Applications, right? The rest of users are accessing to Gmail without problems.<br>
I don't know if Google stores the users but it's strange that they check it in just some apps.<o:p></o:p></p>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">We've seen it historically for users who initiate logins at specific vanity URL's (e.g.,
<a href="http://gcal.lbl.gov">http://gcal.lbl.gov</a>) that are have CNAME records pointing to Google.  It's not all of them; Calendar has historically been the worst.  We've never had problems with Gmail.  After wasting too much time on it, my solution for
 users has been, "Don't do that."  I probably should have just removed the domain mapping.  <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">AFAIK, it has not happened to users when visiting the direct service URL's.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm">
<p class="MsoNormal"><br>
The assertion is quite simple as we only send the mail attribute.<br>
<br>
I've found this link <a href="https://developers.google.com/admin-sdk/reports/v1/appendix/activity/saml" target="_blank">
https://developers.google.com/admin-sdk/reports/v1/appendix/activity/saml</a>, maybe we can try to lookup the SP logs...<o:p></o:p></p>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Those logs are for the G Suite IdP, not the SP.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Greg<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0cm 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm">
<p class="MsoNormal">If we find the answer, we'll post it.<br>
<br>
<br>
Miguel Salinas Vivancos<br>
Identity Management Integrator <br>
Tel.: +34 639 198 154 - <a href="mailto:mail%3Amsalinas@bcn.sia.es" target="_blank">
mail:msalinas@bcn.sia.es</a><br>
<br>
Grupo SIA<br>
Citypark, Edificio Atenas, Ctra. Hospitalet 147. 08940 Cornellá de Llobregat - Barcelona<br>
<a href="http://www.sia.es" target="_blank">www.sia.es</a>  - Twitter: @SIA_es  - LinkedIn: Grupo SIA<br>
<br>
<br>
-----Mensaje original-----<br>
De: users [mailto:<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>] En nombre de Losen, Stephen C (scl)<br>
Enviado el: martes, 3 de septiembre de 2019 12:31<br>
Para: Shib Users<br>
Asunto: RE: Massive authentications from SP GoogleApps<br>
<br>
Hi Miguel,<br>
<br>
I have seen looping like this, but not necessarily involving Google. The user visits the SP, which redirects the user to our IDP for authentication. After success, the IDP redirects the user back to the SP. However, the SP does not accept the credentials (assertion).
 Perhaps the SP has its own database of users and the SP fails to find the user. Perhaps the assertion for this user is unacceptable for some other reason. The SP should display an error page, but instead lets the user try again. The SP redirects the user back
 to our IDP for authentication with a new auth request. But this time the user has an IDP session, so the IDP displays no login page and redirects the user back to the SP with another assertion, which the SP rejects. And this sets up a redirect loop.<br>
<br>
The IDP is unaware of any problem and the IDP logs show no errors. But the logs do show a large number of normal logins to the same SP by the same user.
<br>
<br>
Steve Losen<br>
ITS - Enterprise Infrastructure<br>
University of Virginia<br>
mailto:<a href="mailto:scl@virginia.edu" target="_blank">scl@virginia.edu</a>    434-924-0640<br>
<br>
From: users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> On Behalf Of Miguel Salinas Vivancos<br>
Sent: Monday, September 2, 2019 1:04 PM<br>
To: <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
Subject: Massive authentications from SP GoogleApps<br>
<br>
Hi,<br>
We are using Shibboleth IDP 3.4.4 over Java 1.8, deployed in a Tomcat 8.5.<br>
We have multiple SPs configured to authenticate against our IDP, including big commercial ones like Amazon, Adobe and Microsoft.<br>
<br>
Our problem is that sometimes (maybe once or twice a week), we receive a huge amount of authentications from GoogleApps.<br>
I'm talking over 250 logins in a few seconds when the average for that SP is 5 per minute.
<br>
<br>
At the logs we have seen that on that peek the user is always the same, and Shibboleth is generating different sessions. On different peeks, the users are different so it doesn't seem a problem of specific users.<br>
<br>
This also happened to us with IDP 3.1.2 over Java 1.7 in a Tomcat 7, so the version of the components neither seems to be the problem.<br>
<br>
Has anyone faced something similar? Maybe one of the applications of GoogleApps or the OS/device of the users?<br>
<br>
Thank you in advance<br>
<br>
<br>
Miguel Salinas Vivancos<br>
Identity Management Integrator <br>
Tel.: +34 639 198 154 - <a href="mailto:mail%3Amsalinas@bcn.sia.es" target="_blank">
mail:msalinas@bcn.sia.es</a><br>
<br>
Grupo SIA<br>
Citypark, Edificio Atenas, Ctra. Hospitalet 147. 08940 Cornellá de Llobregat - Barcelona<br>
<a href="http://www.sia.es/" target="_blank">http://www.sia.es/</a>  - Twitter: @SIA_es  - LinkedIn: Grupo SIA<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</blockquote>
</div>
</div>
</div>
</body>
</html>