<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Segoe UI Symbol";
        panose-1:2 11 5 2 4 2 4 2 2 3;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman",serif;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Andy,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><br>
Don’t know if others have forked this work and ported things to the new AWS CLI version. Our developer is looking into this, though, and I’ll post back here with his findings.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Keith<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><a name="_MailEndCompose"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></a></p>
<span style="mso-bookmark:_MailEndCompose"></span>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users <users-bounces@shibboleth.net>
<b>On Behalf Of </b>Morgan, Andrew Jason<br>
<b>Sent:</b> Thursday, February 20, 2020 1:01 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: AWS ECP with awscli-login<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">Keith,<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">Okay, I suspected it might be something like that. 
</span><span style="font-family:"Segoe UI Symbol",sans-serif;color:black">🙂</span><span style="font-family:"Arial",sans-serif;color:black"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">I have awscli-login working in my test environment after making that change.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">Next question - Does anyone have this working with v2 of the aws cli?  I installed that first, but it uses an embedded Python interpreter.  When I ran "pip3 install awscli-login",
 it pulled v1.18.3 of the aws cli into pip (which is what I used for testing).<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">Thanks,<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">Andy<o:p></o:p></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="divRplyFwdMsg">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black"> users <users-bounces@shibboleth.net> on behalf of Wessel, Keith
 <kwessel@illinois.edu><br>
<b>Sent:</b> Thursday, February 20, 2020 10:29 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> RE: AWS ECP with awscli-login</span> <o:p></o:p></p>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">Andy,<br>
<br>
You've hit upon the dirty part of the implementation. I believe this is documented in the readme or the Github wiki for the project. If not, somebody please let me know so we can add it. The basic idea is:<br>
<br>
Step 1: take Scott's advice and don't remotely consume Amazon's metadata. You can pull it down once, but then store it locally and don't refresh it.<br>
Step 2: Add an ECP endpoint. The same ACS URL that you use to send web-based ACS responses to can be used. We added this:<br>
<br>
    <AssertionConsumerService index="2" isDefault="true" Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__signin.aws.amazon.com_saml-2522_&d=DwMGaQ&c=OCIEmEwdEq_aNlsP4fF3gFqSN-E3mlr2t9JcDdfOZag&r=2ERBnv_hmATkLrFo9IGgSTIJkkZL1ljF18WCoTc8nrI&m=PzyV8rTIeXd89sxiOBCEVtaPT3D4EoiZ_zb5gWMzVGI&s=cm5QItgbtsJ_hIGRElRMZhc_4NhcykBAQniDzn2Dkno&e=">https://signin.aws.amazon.com/saml"/</a>><br>
<br>
Note you'll need to mke the same modification to the AWS Gov metadata if you're using that separate AWS instance.<br>
<br>
Keith<br>
<br>
<br>
<br>
From: users <users-bounces@shibboleth.net> On Behalf Of Morgan, Andrew Jason<br>
Sent: Thursday, February 20, 2020 11:55 AM<br>
To: users@shibboleth.net<br>
Subject: AWS ECP with awscli-login<br>
<br>
I'm running into an issue with Illinois' awscli-login module.  When I run "aws login" to perform the ECP authentication, awscli-login sends a SAMLRequest to my IDP's ECP endpoint.  This generates the following error in my IDP logs:<br>
<br>
WARN [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:410] - Profile Action PopulateBindingAndEndpointContexts: Unable to resolve outbound message endpoint for relying party 'urn:amazon:webservices': EndpointCriterion [type={urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService,
 Binding=urn:oasis:names:tc:SAML:2.0:bindings:PAOS, Location=https://urldefense.proofpoint.com/v2/url?u=https-3A__signin.aws.amazon.com_saml&d=DwQFAw&c=OCIEmEwdEq_aNlsP4fF3gFqSN-E3mlr2t9JcDdfOZag&r=2ERBnv_hmATkLrFo9IGgSTIJkkZL1ljF18WCoTc8nrI&m=P_VC6cUV3M9VyJ3Prd26_vbeli35MjsnLANmoYUUlPg&s=c7QkMF1uINQ4RhxCgcxQnokX1aVqckNC1lWPd4ZszPY&e=,
 trusted=false]<br>
WARN [org.opensaml.profile.action.impl.LogEvent:105] - A non-proceed event occurred while processing the request: EndpointResolutionFailed<br>
WARN [net.shibboleth.idp.saml.profile.impl.SpringAwareMessageEncoderFactory:96] - Binding URI was not available, unable to lookup message encoder<br>
ERROR [org.opensaml.profile.action.impl.EncodeMessage:122] - Profile Action EncodeMessage: Unable to locate an outbound message encoder<br>
<br>
The metadata loaded dynamically from Amazon (<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__signin.aws.amazon.com_static_saml-2Dmetadata.xml&d=DwMFAw&c=OCIEmEwdEq_aNlsP4fF3gFqSN-E3mlr2t9JcDdfOZag&r=2ERBnv_hmATkLrFo9IGgSTIJkkZL1ljF18WCoTc8nrI&m=P_VC6cUV3M9VyJ3Prd26_vbeli35MjsnLANmoYUUlPg&s=TT6r-rHsQmXhSh1hCYAVSUL5HJIB5Cc2mh9jvOgzJhc&e=">https://urldefense.proofpoint.com/v2/url?u=https-3A__signin.aws.amazon.com_static_saml-2Dmetadata.xml&d=DwMFAw&c=OCIEmEwdEq_aNlsP4fF3gFqSN-E3mlr2t9JcDdfOZag&r=2ERBnv_hmATkLrFo9IGgSTIJkkZL1ljF18WCoTc8nrI&m=P_VC6cUV3M9VyJ3Prd26_vbeli35MjsnLANmoYUUlPg&s=TT6r-rHsQmXhSh1hCYAVSUL5HJIB5Cc2mh9jvOgzJhc&e=</a>)
 has just 1 ACS entry:<br>
<br>
<AssertionConsumerService index="1" isDefault="true" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://urldefense.proofpoint.com/v2/url?u=https-3A__signin.aws.amazon.com_saml-2522_-253E&d=DwQFAw&c=OCIEmEwdEq_aNlsP4fF3gFqSN-E3mlr2t9JcDdfOZag&r=2ERBnv_hmATkLrFo9IGgSTIJkkZL1ljF18WCoTc8nrI&m=P_VC6cUV3M9VyJ3Prd26_vbeli35MjsnLANmoYUUlPg&s=VtKpP2gHvn4ScdbzFDEOEy863VlKE15_lv8OMHTQ9wo&e=<br>
<br>
So, Shibboleth is definitely correct that there is no PAOS binding for this SP.<br>
<br>
Am I doing something wrong?  How have other awscli-login users solved this issue?<br>
<br>
Thanks,<br>
Andy Morgan<br>
Identity & Access Management<br>
Oregon State University<br>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwMGaQ&c=OCIEmEwdEq_aNlsP4fF3gFqSN-E3mlr2t9JcDdfOZag&r=2ERBnv_hmATkLrFo9IGgSTIJkkZL1ljF18WCoTc8nrI&m=PzyV8rTIeXd89sxiOBCEVtaPT3D4EoiZ_zb5gWMzVGI&s=vb9eZeMG1P84qPrrVWj4OS2hp07Iw8CNxiyNjnR3O1w&e=">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</body>
</html>