<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
span.EmailStyle20
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle21
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal" style="margin-bottom:12.0pt">Building up a new Shib v4.0.1 IdP (under WS2019) utilizing Azure AD for a hybrid release.<o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt">Finished running through the documentation steps a few days ago but running into some issues with crosswalk mapping. I’ve enabled SAML debugging to isolate the issue but not sure where the adjustment needs to
be made.<o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Courier New"">2021-03-01 12:37:13,960 - 143.200.128.40 - DEBUG [org.opensaml.saml.saml2.profile.impl.ValidateAssertions:329] - Profile Action ValidateAssertions: Assertion validation
result was: VALID<br>
2021-03-01 12:37:13,960 - 143.200.128.40 - INFO [Shibboleth-Audit.SSO:282] - 143.200.128.40||2021-03-01T18:37:13.960349500Z||https://sts.windows.net/7fc34f9d-1f75-4f96-b5b3-3cdcxxxxxxxx/|_d92d198a-ea74-4517-babe-37533dae0200|password|2021-03-01T18:37:04.031Z|azureObjectidentifier,azureIdentityprovider,azureGivenname,azureAuthnmethodsreferences,azureDisplayname,azureTenantid,azureEmailaddress,azureSurname|samltest@uwgb.edu|emailAddress||false||Redirect|POST||Success|||Mozilla/5.0
(Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36<br>
<span style="background:yellow;mso-highlight:yellow">2021-03-01 12:37:13,975 - 143.200.128.40 - ERROR [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:78] - Profile Action SelectSubjectCanonicalizationFlow: No potential flows left to choose
from, canonicalization will fail</span><br>
2021-03-01 12:37:13,975 - 143.200.128.40 - INFO [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:142] - Profile Action SelectAuthenticationFlow: Moving incomplete flow authn/SAML to intermediate set<br>
2021-03-01 12:37:13,975 - 143.200.128.40 - INFO [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:316] - Profile Action SelectAuthenticationFlow: No potential flows left to choose from, authentication failed<br>
2021-03-01 12:37:13,975 - 143.200.128.40 - DEBUG [org.opensaml.saml.common.profile.logic.DefaultLocalErrorPredicate:172] - Error event NoPotentialFlow will be handled with response<br>
2021-03-01 12:37:13,975 - 143.200.128.40 - DEBUG [org.opensaml.saml.saml2.profile.impl.AbstractResponseShellAction:216] - Profile Action AddStatusResponseShell: Setting Issuer to https://idpdev.uwgb.edu/idp/shibboleth<br>
2021-03-01 12:37:13,975 - 143.200.128.40 - DEBUG [org.opensaml.saml.common.profile.impl.AddInResponseToToResponse:107] - Profile Action AddInResponseToToResponse: Attempting to add InResponseTo to outgoing Response<br>
2021-03-01 12:37:13,975 - 143.200.128.40 - DEBUG [org.opensaml.saml.saml2.profile.impl.AddStatusToResponse:191] - Profile Action AddStatusToResponse: Detailed errors are disabled<br>
2021-03-01 12:37:13,975 - 143.200.128.40 - DEBUG [org.opensaml.saml.saml2.profile.impl.AddStatusToResponse:220] - Profile Action AddStatusToResponse: Setting StatusMessage to defaulted value<br>
2021-03-01 12:37:13,975 - 143.200.128.40 - DEBUG [org.opensaml.saml.common.binding.impl.SAMLOutboundDestinationHandler:62] - Adding destination to outbound SAML 2 protocol message: https://spdev.uwgb.edu/Shibboleth.sso/SAML2/POST<br>
2021-03-01 12:37:13,975 - 143.200.128.40 - DEBUG [org.opensaml.saml.common.binding.security.impl.EndpointURLSchemeSecurityHandler:52] - Message Handler: Checking outbound endpoint for allowed URL scheme: https://spdev.uwgb.edu/Shibboleth.sso/SAML2/POST<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-bottom:12.0pt">I’m assuming the issue is with Proxy Task 4 which has been setup.<o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt">Attribute-resolver set to:<o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Courier New""><AttributeDefinition xsi:type="SubjectDerivedAttribute" forCanonicalization="true" id="canonicalNameToUseForJoin" principalAttributeName="azureName" /><br>
<AttributeDefinition xsi:type="SubjectDerivedAttribute" forCanonicalization="false" id="mail" principalAttributeName="azureEmailaddress" /><br>
<AttributeDefinition xsi:type="SubjectDerivedAttribute" forCanonicalization="false" id="displayName" principalAttributeName="azureDisplayname" /><br>
<AttributeDefinition xsi:type="SubjectDerivedAttribute" forCanonicalization="false" id="eduPersonPrincipalName" principalAttributeName="azureName" /><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Courier New"">The two extra definitions to the c14n have been added as well. In this config, I’m hoping to doing a basic release via Azure AD attributes, then add in the rest of the
attributes via ldap to AD locally.<o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:#006A4D">Patrick Goggins<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:"Arial",sans-serif;color:#006A4D">Senior Network/Systems Administrator<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:"Arial",sans-serif;color:#006A4D">............................................................................................<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:"Arial",sans-serif;color:#006A4D">Division of Information Technology<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:"Arial",sans-serif;color:#006A4D">University of Wisconsin – Green Bay</span><span style="font-size:8.5pt;font-family:"Arial",sans-serif"><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Courier New""><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Courier New""><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-family:"Courier New""><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><o:p> </o:p></p>
</div>
</body>
</html>