<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><span style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);" class="">Yeah, so I have a ticket open with them, but I’m not sure how far I’ll get.</span><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">All they said was this: </div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">"I understand you're encountering the error outlined here,  which is basically either the SAML assertion was encrypted when your IdP doesn't support encrypted assertions, or the IdP didn't sign both the assertion and the response.</div><br class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><span style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);" class="">Since you have mentioned you tried to unencrypted assertions, would you please check if the Shibboleth is signing both the assertion and the response?”</span><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">——</div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">I have nothing in relying-party.xml for Duo.</div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">I have this in my Duo metadata: </div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"> <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol”></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">So that looks good I guess?</div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">In the Duo Panel I have </div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">Encrypt Assertions: Require encrypted assertions</div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">Request signing: Do not sign messages from Duo</div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">------------</div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">The Certificate for signing is in the Duo Metadata file. I double checked that looks right.</div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);">My attribute filter is this:</div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><br class=""></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><AttributeFilterPolicy id="releaseForDuo" ><br class="">  <PolicyRequirementRule xsi:type="RequesterRegex" regex="https:\/\/admin-ourduonumber\.duosecurity\.com\/.*" /><br class="">        <AttributeRule attributeID="mail" permitAny="true" /><br class=""></AttributeFilterPolicy></div><div class="" style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);"><div class=""><br class=""></div><div class="">(Ourduonumber is the weird number they add to the end of admin-)</div><div class=""><br class=""></div><div class="">——</div><div class=""><br class=""></div><div class="">I’m really not sure what else to try.</div><div class=""><br class=""></div><div class="">Thanks again for all your help and replies. </div><div class=""><br class=""></div><div class="">Appreciate it.</div></div><div class="">
<div style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"><span style="font-size: 14px;" class=""><font color="#007236" class=""><b class="">Melvin Lasky</b><br class="">Associate Director of Enterprise Architecture</font></span></div><div style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"><span style="font-size: 14px;" class="">Riverdale, NY 10471<br class="">Phone: 718-862-7410<br class=""><a href="mailto:melvin.lasky@manhattan.edu" class="">melvin.lasky@manhattan.edu</a><br class="">www.manhattan.edu</span><br class=""><br class=""></div>
</div>
<div><br class=""><blockquote type="cite" class=""><div class="">On Jan 27, 2022, at 7:07 PM, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" class="">cantor.2@osu.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class="">On 1/27/22, 7:02 PM, "Melvin Lasky" <<a href="mailto:melvin.lasky@manhattan.edu" class="">melvin.lasky@manhattan.edu</a>> wrote:<br class=""><br class=""><blockquote type="cite" class="">   Ok yeah, so I do have the WantAssertionsSigned in the metadata from Duo. It came like that. <br class="">   So I’m really at a loss as to what I’m supposed to do here :-(<br class=""></blockquote><br class="">You can do some log or browser tracing just to verify that it's doing what it should be, but unless they actually require encryption (I don't recall, just that we are doing it), there has to be something else wrong. Either they have logs saying what that is or I don't see what you can really do other than a whole lot of trial and error.<br class=""><br class="">I'm passing email address in standard fashion, so I presume it must have settings there controlling how it maps that in. Maybe that's not set up right.<br class=""><br class="">-- Scott<br class=""><br class=""><br class=""></div></div></blockquote></div><br class=""></body></html>