<div dir="ltr">Thanks, But no luck,<div> Errors below</div><div><br>2021-02-01 21:43:29,907 - 10.0.7.6 - ERROR [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:78] - Profile Action SelectSubjectCanonicalizationFlow: No potential flows left to choose from, canonicalization will fail<br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, Feb 1, 2021 at 8:43 PM Chris Phillips <<a href="mailto:Chris.Phillips@canarie.ca">Chris.Phillips@canarie.ca</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div lang="EN-CA" style="overflow-wrap: break-word;"><div class="gmail-m_-1136210883276491281WordSection1"><p class="MsoNormal">Hi Raja..<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">Matthew an David’s prior comments are on point:<u></u><u></u></p><ul style="margin-top:0cm" type="disc"><li class="gmail-m_-1136210883276491281MsoListParagraph" style="margin-left:0cm">Ensure you are releasing attributes from Azure in the Relying Party configuration in Azure (Trust Task 4)<u></u><u></u></li><li class="gmail-m_-1136210883276491281MsoListParagraph" style="margin-left:0cm">David’s comment on the unspecified item is what I encountered as well and why the Proxy Task 3 step is needed to ingest the Azure attributes as unspecified in nature<u></u><u></u></li><li class="gmail-m_-1136210883276491281MsoListParagraph" style="margin-left:0cm">Increasing log level to DEBUG is a great instrument to better understand what’s happening there<u></u><u></u></li></ul><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">That should reveal how well (or not) things flow and hopefully reveal next steps.<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">Note that the example in Proxy Task 3 is not exhaustive of all attributes you may want. You will likely need more definitions depending on what you require from Azure AD so expect to add more in that small set.<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal">C.<u></u><u></u></p><p class="MsoNormal"><u></u> <u></u></p><p class="MsoNormal"><u></u> <u></u></p><div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(181,196,223);padding:3pt 0cm 0cm"><p class="MsoNormal"><b><span style="font-size:12pt;color:black">From: </span></b><span style="font-size:12pt;color:black">"<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of "Raja V, Scientist - C (CS)" <<a href="mailto:raja@inflibnet.ac.in" target="_blank">raja@inflibnet.ac.in</a>><br><b>Reply-To: </b>SHIB-USERS <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br><b>Date: </b>Monday, February 1, 2021 at 1:00 AM<br><b>To: </b>SHIB-USERS <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br><b>Cc: </b>Francis Jayakanth <<a href="mailto:Francis@iisc.ac.in" target="_blank">Francis@iisc.ac.in</a>><br><b>Subject: </b>Azure AD and shibboleth IdP integration<u></u><u></u></span></p></div><div><p class="MsoNormal"><u></u> <u></u></p></div><div><p class="MsoNormal"><span style="font-family:"Trebuchet MS",sans-serif">Hi,</span><u></u><u></u></p><div><p class="MsoNormal"><span style="font-family:"Trebuchet MS",sans-serif">We are trying to integrate Azure AD with shibboleth by following document available at <a href="https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+in+the+Shibboleth+IdP+to+connect+with+Azure+AD" target="_blank">https://wiki.shibboleth.net/confluence/display/KB/Using+SAML+Proxying+in+the+Shibboleth+IdP+to+connect+with+Azure+AD</a></span><u></u><u></u></p></div><div><p class="MsoNormal"><u></u> <u></u></p></div><div><p class="MsoNormal"><span style="font-family:"Trebuchet MS",sans-serif">However, after authentication, we are getting the following error. Can anyone help us out?</span><u></u><u></u></p></div><div><p class="MsoNormal"><u></u> <u></u></p><div><p class="MsoNormal"><i><span style="font-family:"Trebuchet MS",sans-serif;color:black;background:yellow">2021-02-01 11:21:53,314 - 10.0.7.6 - INFO [Shibboleth-Audit.SSO:282] - 10.0.7.6||2021-02-01T05:51:53.314018Z||<a href="https://sts.windows.net" target="_blank">https://sts.windows.net</a>******/|_282b0ffa-9537-4b9c-9444-bbaf4bee7700|password|2021-02-01T04:42:10.204Z|azureObjectidentifier,azureIdentityprovider,azureGivenname,azureDisplayname,azureAuthnmethodsreferences,azureTenantid,azureEmailaddress,azureSurname|<a href="mailto:email@email.org" target="_blank">email@email.org</a>|emailAddress||false||Redirect|POST||Success|||Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.104 Safari/537.36<br>2021-02-01 11:21:53,388 - 10.0.7.6 - ERROR [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:78] - Profile Action SelectSubjectCanonicalizationFlow: No potential flows left to choose from, canonicalization will fail<br>2021-02-01 11:21:53,390 - 10.0.7.6 - INFO [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:142] - Profile Action SelectAuthenticationFlow: Moving incomplete flow authn/SAML to intermediate set<br>2021-02-01 11:21:53,390 - 10.0.7.6 - INFO</span></i><span style="font-family:"Trebuchet MS",sans-serif"> [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:316] - Profile Action SelectAuthenticationFlow: No potential flows left to choose from, authentication failed<br> </span><u></u><u></u></p></div></div></div></div></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>