<div dir="ltr">When I try to login to <a href="http://node1.server.com">node1.server.com</a>, it redirects me to login page of <a href="http://server.example.com">server.example.com</a>. Here are the steps. Not sure how to troubleshoot this.<div><br></div><div>I first try to login to node1 page</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><a href="https://node1.example.org/jira">https://node1.example.org/jira</a></blockquote><div><br></div><div>It takes me to signon page</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><a href="https://server.example.org/shibboleth-ds/index.html?entityID=https://node1.example.org&return=https://node1.example.org/Shibboleth.sso/Login?SAMLDS=1&target=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3">https://server.example.org/shibboleth-ds/index.html?entityID=https://node1.example.org&return=https://node1.example.org/Shibboleth.sso/Login?SAMLDS=1&target=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3</a></blockquote><div><br></div><div>I click on signon button which links to below</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><a href="https://server.example.org/Shibboleth.sso/Login?SAMLDS=1&target=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3&entityID=http://ssotest.example.org/adfs/services/trust">https://server.example.org/Shibboleth.sso/Login?SAMLDS=1&target=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3&entityID=http://ssotest.example.org/adfs/services/trust</a></blockquote><div><br></div><div>On the chrome Network console I see the samlrequest</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><a href="https://ssotest.example.org/adfs/ls/?SAMLRequest=....&RelayState=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3&SigAlg=http://www.w3.org/2001/04/xmldsig-more#rsa-sha256&Signature=f3esrxiTFWYxo2KDSsNBdXAADsQ/YBhohzY8z6x3PTtETpc7gl0VviXNwAEpcLp7LitGfd82nqiNU32E/nUWVnO37fJGyuUFnaAIhQcXeGxI6nGTy+HWiCouuVDgdMXrzvf/M5K7rS3cw1tbOoGPAeiEUv8xh5aR1v6c0XjUTno9ZC2ERo7OtEhPA6F/sCdK4e0eGnx0RCop2PLdVdeprPk25gczGjBwhKxsx3wxFeqRU/OqMepmFLB3SBqXXRaEy1ekyE0Hqb9axYhdJqn85j9Dl3eOpkKwabZdjDF010GYy4p2vJo3qzu+RB+N8NL75XXbWn3Q==">https://ssotest.example.org/adfs/ls/?SAMLRequest=....&RelayState=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3&SigAlg=http://www.w3.org/2001/04/xmldsig-more#rsa-sha256&Signature=f3esrxiTFWYxo2KDSsNBdXAADsQ/YBhohzY8z6x3PTtETpc7gl0VviXNwAEpcLp7LitGfd82nqiNU32E/nUWVnO37fJGyuUFnaAIhQcXeGxI6nGTy+HWiCouuVDgdMXrzvf/M5K7rS3cw1tbOoGPAeiEUv8xh5aR1v6c0XjUTno9ZC2ERo7OtEhPA6F/sCdK4e0eGnx0RCop2PLdVdeprPk25gczGjBwhKxsx3wxFeqRU/OqMepmFLB3SBqXXRaEy1ekyE0Hqb9axYhdJqn85j9Dl3eOpkKwabZdjDF010GYy4p2vJo3qzu+RB+N8NL75XXbWn3Q==</a></blockquote><div><br></div><div>SAMLRequest is</div><div><br></div><div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<br> AssertionConsumerServiceURL="<a href="https://server.example.org/Shibboleth.sso/SAML2/POST">https://server.example.org/Shibboleth.sso/SAML2/POST</a>"<br> Destination="<a href="https://ssotest.example.org/adfs/ls/">https://ssotest.example.org/adfs/ls/</a>"<br> ID="_dafedbb9424fd98c192d040ba9833"<br> IssueInstant="2021-07-14T14:11:00Z"<br> ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><br><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><br><a href="https://server.example.org">https://server.example.org</a><br></saml:Issuer><br><samlp:NameIDPolicy AllowCreate="1"/></blockquote><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"></samlp:AuthnRequest></blockquote></div><div><br></div><div>Then takes me back to the login page of the server. So login to node1 never worked. The next three steps on Network console are</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">GET <a href="https://ssotest.example.org/favicon.ico">https://ssotest.example.org/favicon.ico</a><br>POST <a href="https://server.example.org/Shibboleth.sso/SAML2/POST">https://server.example.org/Shibboleth.sso/SAML2/POST</a><br>GET <a href="https://server.example.org/">https://server.example.org/</a></blockquote><div><br></div><div>I am kind a lost. Any suggestion on what is going on and how to troubleshoot this?</div><div><br></div><div>Thanks,</div><div>Asif</div><div><br></div><div> </div><div><br></div><div> </div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Jul 8, 2021 at 4:04 AM Alan Buxey via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">hi,<br>
<br>
> We recently got into a situation where our SP cert expired and we only found out the next morning when everyone was trying to login, yikes! We remedy the situation and monitoring the cert.<br>
<br>
<br>
your Shibboleth/SAML cert expired, or your service cert<br>
(apache/IIS/whatever) cert expired?<br>
<br>
in terms of monitoring, know when your cert expires, you don't want to<br>
only know when logs are showing you its expired. stick expiry dates<br>
in calendars AND run a monitoring tool that checks your certificate<br>
expiry dates on public services (eg a NAGIOS plugin etc)<br>
<br>
alan<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature">Asif Iqbal<br>PGP Key: 0xE62693C5 KeyServer: <a href="http://pgp.mit.edu" target="_blank">pgp.mit.edu</a><br>A: Because it messes up the order in which people normally read text.<br>Q: Why is top-posting such a bad thing?<br><br></div>