<div dir="ltr"><div>Hi Scott,</div><div><br></div><div>We had turned on the logging as "DEBUG" level but it did not give us enough information. We also tried on a working sp metadata by just replacing this certificate which caused the error; and we also got the "Message was signed, but signature could not be verified" error. Do you have any suggestions on how to troubleshoot or fix this?</div><div><br></div><div>-Terry</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Feb 3, 2023 at 4:00 AM <<a href="mailto:users-request@shibboleth.net">users-request@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>
<u></u>
<div>
<h1 style="background-color:rgb(255,255,179);font-family:arial;font-size:13px;color:rgb(255,0,0);border:1px dotted rgb(0,0,0)">CAUTION: This email originated from an external sender. Always use caution when opening links or attachments from external parties.</h1>
</div>
Send users mailing list submissions to<br>
<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
<br>
To subscribe or unsubscribe via the World Wide Web, visit<br>
<a href="https://shibboleth.net/mailman/listinfo/users" target="_blank">https://shibboleth.net/mailman/listinfo/users</a><br>
or, via email, send a message with subject or body 'help' to<br>
<a href="mailto:users-request@shibboleth.net" target="_blank">users-request@shibboleth.net</a><br>
<br>
You can reach the person managing the list at<br>
<a href="mailto:users-owner@shibboleth.net" target="_blank">users-owner@shibboleth.net</a><br>
<br>
When replying, please edit your Subject line so it is more specific<br>
than "Re: Contents of users digest..."<br>
<br>
<br>
Today's Topics:<br>
<br>
1. Documentation on 'e' and 's' in execution=eXsY (Jeff Chapin)<br>
2. Re: Shibboleth SP saml assertion signature validation failure<br>
(Cantor, Scott)<br>
3. Re: Documentation on 'e' and 's' in execution=eXsY (Cantor, Scott)<br>
4. Re: Documentation on 'e' and 's' in execution=eXsY (Jeff Chapin)<br>
5. Re: Documentation on 'e' and 's' in execution=eXsY (Cantor, Scott)<br>
6. InCommon: Register now for Shibboleth Training & More <br>
(Jean Chorazyczewski)<br>
7. Re: Documentation on 'e' and 's' in execution=eXsY (Jeff Chapin)<br>
8. Re: Documentation on 'e' and 's' in execution=eXsY (Cantor, Scott)<br>
9. Re: Documentation on 'e' and 's' in execution=eXsY<br>
(Morgan, Andrew J)<br>
10. Re: Documentation on 'e' and 's' in execution=eXsY (Jeff Chapin)<br>
11. Validation failure: Failed to resolve an encryption key<br>
(Mohamed Lrhazi)<br>
12. Re: Documentation on 'e' and 's' in execution=eXsY (Chris Reeves)<br>
<br>
<br>
----------------------------------------------------------------------<br>
<br>
Message: 1<br>
Date: Thu, 2 Feb 2023 06:49:48 -0600<br>
From: Jeff Chapin <<a href="mailto:jeff.chapin@uni.edu" target="_blank">jeff.chapin@uni.edu</a>><br>
To: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Documentation on 'e' and 's' in execution=eXsY<br>
Message-ID:<br>
<<a href="mailto:CAHApK_UhQJymxvVy3LHigS7fjAxfDg_gG09y2tOcy1366Og5_g@mail.gmail.com" target="_blank">CAHApK_UhQJymxvVy3LHigS7fjAxfDg_gG09y2tOcy1366Og5_g@mail.gmail.com</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
I am looking for documentation on what the 'e' and the 's' in the string<br>
'execution=eXsY', found in various IDP URLs mean, and I am having a hard<br>
time coming up with meaningful search terms.<br>
<br>
We have an SP that is occasionally having issues, and users fail to login.<br>
When this happens, they are given an internal server error from the IDP,<br>
and I have noticed that the URL typically contains something like<br>
execution=e78s1, which seems relatively high, considering the values I see<br>
in the logs are usually in the low single digits.....<br>
<br>
Thanks,<br>
Jeff<br>
<br>
-- <br>
<br>
Jeff Chapin,<br>
<br>
Panther eSports Adviser<br>
Systems/Applications Administrator<br>
ITS-IS, University of Northern Iowa<br>
Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a><br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20230202/7f4d3bac/attachment-0001.htm" target="_blank">http://shibboleth.net/pipermail/users/attachments/20230202/7f4d3bac/attachment-0001.htm</a>><br>
<br>
------------------------------<br>
<br>
Message: 2<br>
Date: Thu, 2 Feb 2023 13:19:33 +0000<br>
From: "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>><br>
To: "<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>" <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Re: Shibboleth SP saml assertion signature validation failure<br>
Message-ID: <<a href="mailto:5F0C3F9B-D32D-439D-9E04-78F125F586CD@osu.edu" target="_blank">5F0C3F9B-D32D-439D-9E04-78F125F586CD@osu.edu</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
> We noticed that our customer's public cert has a size of 2237, all our<br>
> other adfs customer's cert size is less than 2k, we suspected that might<br>
> be an issue.<br>
<br>
If it were, the log would say so. Otherwise the error is exactly what it says it is, the metadata's wrong. No amount of claims that "we checked it" is relevant to that question.<br>
<br>
-- Scott <br>
<br>
<br>
<br>
------------------------------<br>
<br>
Message: 3<br>
Date: Thu, 2 Feb 2023 13:55:54 +0000<br>
From: "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>><br>
To: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Re: Documentation on 'e' and 's' in execution=eXsY<br>
Message-ID: <<a href="mailto:BF197E7D-2B78-4503-AF0D-D2628F552021@osu.edu" target="_blank">BF197E7D-2B78-4503-AF0D-D2628F552021@osu.edu</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
> I am looking for documentation on what the 'e' and the 's' in the string<br>
> 'execution=eXsY', found in various IDP URLs mean,<br>
<br>
They aren't somethiing to document, it's an internal detail of Spring WebFlow.<br>
The entire parameter name and value are opaque, in an official sense, but there's probably some kind of description of them in the SWF documentation. What they are in the implementation is an execution/conversation number and a state number.<br>
<br>
> I have noticed that the URL typically contains something like execution=e78s1,<br>
> which seems relatively high, considering the values I see in the logs are usually<br>
> in the low single digits.....<br>
<br>
That's an SSO loop. Most loops these days are caused by the abomination of AJAX combined with a failure to deal with timeouts.<br>
<br>
-- Scott<br>
<br>
<br>
<br>
------------------------------<br>
<br>
Message: 4<br>
Date: Thu, 2 Feb 2023 08:08:33 -0600<br>
From: Jeff Chapin <<a href="mailto:jeff.chapin@uni.edu" target="_blank">jeff.chapin@uni.edu</a>><br>
To: "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>><br>
Cc: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Re: Documentation on 'e' and 's' in execution=eXsY<br>
Message-ID:<br>
<<a href="mailto:CAHApK_W1ttApjNUFODURnHf_LVfb2S9U0AStc0049uUdU58jRA@mail.gmail.com" target="_blank">CAHApK_W1ttApjNUFODURnHf_LVfb2S9U0AStc0049uUdU58jRA@mail.gmail.com</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
Thanks, I was guessing it was a loop -- and I think I even found what<br>
causes it to end -- each time through the loop, they appear to be appending<br>
more header information, until apache, which we are using as a reverse<br>
proxy, finally chokes on it. Incidentally, it seems like cache/timeouts are<br>
a factor in this. Thank you for validating my thoughts -- this gives me<br>
enough to point fingers at the vendor and not let them point them back.<br>
<br>
Jeff<br>
<br>
On Thu, Feb 2, 2023 at 7:55 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br>
<br>
> > I am looking for documentation on what the 'e' and the 's' in the string<br>
> > 'execution=eXsY', found in various IDP URLs mean,<br>
><br>
> They aren't somethiing to document, it's an internal detail of Spring<br>
> WebFlow.<br>
> The entire parameter name and value are opaque, in an official sense, but<br>
> there's probably some kind of description of them in the SWF documentation.<br>
> What they are in the implementation is an execution/conversation number and<br>
> a state number.<br>
><br>
> > I have noticed that the URL typically contains something like<br>
> execution=e78s1,<br>
> > which seems relatively high, considering the values I see in the logs<br>
> are usually<br>
> > in the low single digits.....<br>
><br>
> That's an SSO loop. Most loops these days are caused by the abomination of<br>
> AJAX combined with a failure to deal with timeouts.<br>
><br>
> -- Scott<br>
><br>
><br>
><br>
<br>
-- <br>
<br>
Jeff Chapin,<br>
<br>
Panther eSports Adviser<br>
Systems/Applications Administrator<br>
ITS-IS, University of Northern Iowa<br>
Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a><br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20230202/6c37dddb/attachment-0001.htm" target="_blank">http://shibboleth.net/pipermail/users/attachments/20230202/6c37dddb/attachment-0001.htm</a>><br>
<br>
------------------------------<br>
<br>
Message: 5<br>
Date: Thu, 2 Feb 2023 14:19:39 +0000<br>
From: "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>><br>
To: Jeff Chapin <<a href="mailto:jeff.chapin@uni.edu" target="_blank">jeff.chapin@uni.edu</a>><br>
Cc: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Re: Documentation on 'e' and 's' in execution=eXsY<br>
Message-ID: <<a href="mailto:EE8B9C2F-25B9-4B9E-8E2C-D882D7A9508B@osu.edu" target="_blank">EE8B9C2F-25B9-4B9E-8E2C-D882D7A9508B@osu.edu</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
> Thanks, I was guessing it was a loop -- and I think I even found what causes it to<br>
> end -- each time through the loop, they appear to be appending more header<br>
> information, until apache, which we are using as a reverse proxy, finally chokes<br>
> on it.<br>
<br>
If you mean the IdP is proxied, it doesn't accumulate anything like that between itself and the client. Loops generally won't break unless they break on the SP side or something is done on the IdP to do it (like the feature I added to detect them).<br>
<br>
-- Scott<br>
<br>
<br>
<br>
<br>
------------------------------<br>
<br>
Message: 6<br>
Date: Thu, 2 Feb 2023 14:22:30 +0000<br>
From: Jean Chorazyczewski <<a href="mailto:jeanc@internet2.edu" target="_blank">jeanc@internet2.edu</a>><br>
To: "<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>" <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: InCommon: Register now for Shibboleth Training & More <br>
Message-ID:<br>
<<a href="mailto:BN8PR08MB619629EF5404E464FA721024EAD69@BN8PR08MB6196.namprd08.prod.outlook.com" target="_blank">BN8PR08MB619629EF5404E464FA721024EAD69@BN8PR08MB6196.namprd08.prod.outlook.com</a>><br>
<br>
Content-Type: text/plain; charset="windows-1252"<br>
<br>
Hello all,<br>
<br>
Does your team have a staff member who needs a crash course on Shibboleth<<a href="https://incommon.org/academy/shibboleth" target="_blank">https://incommon.org/academy/shibboleth/</a>>? Today is a good day to register for InCommon?s Shibboleth training workshop ? seats are still available!<br>
<br>
<br>
Shibboleth Workshop<br>
Sessions (via Zoom): February 13-17, 2023 (partial days)<br>
Details and registration can be found on our Shibboleth Workshop<<a href="https://incommon.org/academy/shibboleth/" target="_blank">https://incommon.org/academy/shibboleth/</a>> site.<br>
<br>
What is the Shibboleth Workshop? Shibboleth provides single sign-on (SSO) to services hosted locally or globally using the InCommon Federation. You?ll learn how to install, configure, and customize the IdP and SP to meet the needs of your organization for single sign-on (SSO) that protects both the privacy of your users and your content and services. The virtual workshop is delivered through self-paced learning, access to a class Slack channel, and office hour sessions with instructors delivered through Zoom.<br>
<br>
Learn more and register for Shibboleth training here<<a href="https://incommon.org/academy/shibboleth/" target="_blank">https://incommon.org/academy/shibboleth/</a>>. Registration ends soon!<br>
<br>
_ _ _ _ _<br>
<br>
More Opportunities for Onboarding and Upskilling<br>
InCommon Academy is your one-stop connection to the best options for your team?s IAM Training in 2023.<br>
<br>
<br>
Registration is open for several upcoming workshops on Grouper<<a href="https://incommon.org/academy/grouper-school" target="_blank">https://incommon.org/academy/grouper-school/</a>>, COmanage<<a href="https://incommon.org/academy/comanage" target="_blank">https://incommon.org/academy/comanage/</a>>, and midPoint<<a href="https://incommon.org/academy/midpoint-evolveum" target="_blank">https://incommon.org/academy/midpoint-evolveum/</a>>. Our training lineup offers a blend of virtual workshops spread over the course of a week, combined with self-paced work and hands-on activities hosted in virtual machines. Participants will build the skills and expertise they need.<br>
<br>
<br>
Interested in learning more? View software training highlights for spring 2023 at InCommon Academy<<a href="https://incommon.org/academy" target="_blank">https://incommon.org/academy/</a>>.<br>
<br>
<br>
<br>
_______<br>
<br>
Jean Chorazyczewski | Director, InCommon Academy<br>
Internet2<br>
<br>
Email: <a href="mailto:jeanc@internet2.edu" target="_blank">jeanc@internet2.edu</a><mailto:<a href="mailto:jeanc@internet2.edu" target="_blank">jeanc@internet2.edu</a>><br>
Mobile: +1-734-223-2847<br>
<br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20230202/a9d7a142/attachment-0001.htm" target="_blank">http://shibboleth.net/pipermail/users/attachments/20230202/a9d7a142/attachment-0001.htm</a>><br>
<br>
------------------------------<br>
<br>
Message: 7<br>
Date: Thu, 2 Feb 2023 09:01:12 -0600<br>
From: Jeff Chapin <<a href="mailto:jeff.chapin@uni.edu" target="_blank">jeff.chapin@uni.edu</a>><br>
To: "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>><br>
Cc: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Re: Documentation on 'e' and 's' in execution=eXsY<br>
Message-ID:<br>
<CAHApK_XetyfqSx_Z=JOUiiTV=<a href="mailto:vsf0kU-UFv3EQvvR-x4%2BN7sSQ@mail.gmail.com" target="_blank">vsf0kU-UFv3EQvvR-x4+N7sSQ@mail.gmail.com</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
Strange. I am getting the following in my apache logs, which sits in front<br>
of Tomcat:<br>
AH00971: ajp_marshal_into_msgb: Error appending the header value<br>
AH00988: ajp_send_header: ajp_marshal_into_msgb failed<br>
<br>
The timestamp of this error corresponds to the time users are reporting<br>
errors -- *AND* the URL of the error is the IDP host, and appears to be a<br>
HTTPD error -- not shib or Tomcat. My assumption was that *something* --<br>
the SP, the httpd proxy, the load balancer, or something I can't even think<br>
of was causing something to append headers. We have seen similar errors in<br>
the past when one of our SPs was trying to append a *VERY* long header,<br>
which was longer than the default header length, so I may have jumped to a<br>
false conclusion.<br>
<br>
On Thu, Feb 2, 2023 at 8:19 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br>
<br>
> > Thanks, I was guessing it was a loop -- and I think I even found what<br>
> causes it to<br>
> > end -- each time through the loop, they appear to be appending more<br>
> header<br>
> > information, until apache, which we are using as a reverse proxy,<br>
> finally chokes<br>
> > on it.<br>
><br>
> If you mean the IdP is proxied, it doesn't accumulate anything like that<br>
> between itself and the client. Loops generally won't break unless they<br>
> break on the SP side or something is done on the IdP to do it (like the<br>
> feature I added to detect them).<br>
><br>
> -- Scott<br>
><br>
><br>
><br>
><br>
<br>
-- <br>
<br>
Jeff Chapin,<br>
<br>
Panther eSports Adviser<br>
Systems/Applications Administrator<br>
ITS-IS, University of Northern Iowa<br>
Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a><br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20230202/0f4a412a/attachment-0001.htm" target="_blank">http://shibboleth.net/pipermail/users/attachments/20230202/0f4a412a/attachment-0001.htm</a>><br>
<br>
------------------------------<br>
<br>
Message: 8<br>
Date: Thu, 2 Feb 2023 15:27:08 +0000<br>
From: "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>><br>
To: Jeff Chapin <<a href="mailto:jeff.chapin@uni.edu" target="_blank">jeff.chapin@uni.edu</a>><br>
Cc: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Re: Documentation on 'e' and 's' in execution=eXsY<br>
Message-ID: <<a href="mailto:80ED7426-AF82-4875-B5DF-3479FBA5DAD5@osu.edu" target="_blank">80ED7426-AF82-4875-B5DF-3479FBA5DAD5@osu.edu</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
> We have seen similar errors in the past when one of our SPs was trying to<br>
> append a *VERY* long header, which was longer than the default header length,<br>
> so I may have jumped to a false conclusion. <br>
<br>
My point is the SP might contaminate its own headers with cookies or what have you, but it can't make the requests to the IdP "bigger" apart from via the request URL or body. It can't "add headers" to the IdP requests.<br>
<br>
As for the IdP, I am not aware of any scenario with loops that changes much about the size of the requests. Cookies get replaced perhaps, but not added.<br>
<br>
Even a full login loop in local storage if it happened would replace the SP record with the new one, the cache doesn't track > 1 session per SP.<br>
<br>
-- Scott<br>
<br>
<br>
<br>
<br>
------------------------------<br>
<br>
Message: 9<br>
Date: Thu, 2 Feb 2023 18:07:43 +0000<br>
From: "Morgan, Andrew J" <<a href="mailto:morgan@oregonstate.edu" target="_blank">morgan@oregonstate.edu</a>><br>
To: Jeff Chapin <<a href="mailto:jeff.chapin@uni.edu" target="_blank">jeff.chapin@uni.edu</a>>, Shib Users<br>
<<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Re: Documentation on 'e' and 's' in execution=eXsY<br>
Message-ID:<br>
<<a href="mailto:SJ0P222MB012242C280B73B3271E451A0D1D69@SJ0P222MB0122.NAMP222.PROD.OUTLOOK.COM" target="_blank">SJ0P222MB012242C280B73B3271E451A0D1D69@SJ0P222MB0122.NAMP222.PROD.OUTLOOK.COM</a>><br>
<br>
Content-Type: text/plain; charset="us-ascii"<br>
<br>
I see an AJP error in my Apache logs several times a day as well. Here is an example from yesterday:<br>
<br>
[Wed Feb 01 17:08:29.923773 2023] [proxy_ajp:error] [pid 31685] AH03229: ajp_msg_append_cvt_string(): BufferOverflowException 4 770<br>
[Wed Feb 01 17:08:29.923979 2023] [proxy_ajp:error] [pid 31685] [client <a href="http://10.214.152.45:62219" target="_blank">10.214.152.45:62219</a>] AH00971: ajp_marshal_into_msgb: Error appending the header value, referer: <a href="https://jobs.oregonstate.edu" target="_blank">https://jobs.oregonstate.edu/</a><br>
[Wed Feb 01 17:08:29.924038 2023] [proxy_ajp:error] [pid 31685] [client <a href="http://10.214.152.45:62219" target="_blank">10.214.152.45:62219</a>] AH00988: ajp_send_header: ajp_marshal_into_msgb failed, referer: <a href="https://jobs.oregonstate.edu/" target="_blank">https://jobs.oregonstate.edu/</a><br>
[Wed Feb 01 17:08:29.924073 2023] [proxy_ajp:error] [pid 31685] (120001)APR does not understand this error code: [client <a href="http://10.214.152.45:62219" target="_blank">10.214.152.45:62219</a>] AH00868: request failed to [::1]:8009 (localhost), referer: <a href="https://jobs.oregonstate.edu/" target="_blank">https://jobs.oregonstate.edu/</a><br>
<br>
>From the Apache and IDP logs, this doesn't appear to be a loop. I don't know why the header would be too big, either.<br>
<br>
We're running this on Debian 10 with their latest apache2 and tomcat9 packages.<br>
<br>
Is this the same error that you are seeing Jeff?<br>
<br>
Thanks,<br>
Andy<br>
<br>
________________________________<br>
From: users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Cantor, Scott via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Sent: Thursday, February 2, 2023 7:27 AM<br>
To: Jeff Chapin <<a href="mailto:jeff.chapin@uni.edu" target="_blank">jeff.chapin@uni.edu</a>><br>
Cc: Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>>; Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Re: Documentation on 'e' and 's' in execution=eXsY<br>
<br>
[This email originated from outside of OSU. Use caution with links and attachments.]<br>
<br>
> We have seen similar errors in the past when one of our SPs was trying to<br>
> append a *VERY* long header, which was longer than the default header length,<br>
> so I may have jumped to a false conclusion.<br>
<br>
My point is the SP might contaminate its own headers with cookies or what have you, but it can't make the requests to the IdP "bigger" apart from via the request URL or body. It can't "add headers" to the IdP requests.<br>
<br>
As for the IdP, I am not aware of any scenario with loops that changes much about the size of the requests. Cookies get replaced perhaps, but not added.<br>
<br>
Even a full login loop in local storage if it happened would replace the SP record with the new one, the cache doesn't track > 1 session per SP.<br>
<br>
-- Scott<br>
<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cmorgan%40oregonstate.edu%7C9b6e113a54f7486cd60108db0531fbd7%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638109484452455009%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=ea%2FV7cpPpViBUJiSYIxVp%2B80ZTyxg9R0lEE7%2FZA%2FRqg%3D&reserved=0" target="_blank">https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cmorgan%40oregonstate.edu%7C9b6e113a54f7486cd60108db0531fbd7%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638109484452455009%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=ea%2FV7cpPpViBUJiSYIxVp%2B80ZTyxg9R0lEE7%2FZA%2FRqg%3D&reserved=0</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20230202/e736f28c/attachment-0001.htm" target="_blank">http://shibboleth.net/pipermail/users/attachments/20230202/e736f28c/attachment-0001.htm</a>><br>
<br>
------------------------------<br>
<br>
Message: 10<br>
Date: Thu, 2 Feb 2023 12:49:00 -0600<br>
From: Jeff Chapin <<a href="mailto:jeff.chapin@uni.edu" target="_blank">jeff.chapin@uni.edu</a>><br>
To: "Morgan, Andrew J" <<a href="mailto:morgan@oregonstate.edu" target="_blank">morgan@oregonstate.edu</a>><br>
Cc: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>>, "Cantor, Scott"<br>
<<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>><br>
Subject: Re: Documentation on 'e' and 's' in execution=eXsY<br>
Message-ID:<br>
<CAHApK_W965vS1MWuk=HDG=<a href="mailto:yhnSF4LMfy59HVrRcXaLwT25PnWg@mail.gmail.com" target="_blank">yhnSF4LMfy59HVrRcXaLwT25PnWg@mail.gmail.com</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
It's very similar -- but we don't seem to have the AH03229:<br>
ajp_msg_append_cvt_string(): BufferOverflowException portion. It looks like<br>
we have the rest.<br>
<br>
On Thu, Feb 2, 2023 at 12:07 PM Morgan, Andrew J <<a href="mailto:morgan@oregonstate.edu" target="_blank">morgan@oregonstate.edu</a>><br>
wrote:<br>
<br>
> I see an AJP error in my Apache logs several times a day as well. Here is<br>
> an example from yesterday:<br>
><br>
> [Wed Feb 01 17:08:29.923773 2023] [proxy_ajp:error] [pid 31685] AH03229:<br>
> ajp_msg_append_cvt_string(): BufferOverflowException 4 770<br>
> [Wed Feb 01 17:08:29.923979 2023] [proxy_ajp:error] [pid 31685] [client<br>
> <a href="http://10.214.152.45:62219" target="_blank">10.214.152.45:62219</a>] AH00971: ajp_marshal_into_msgb: Error appending the<br>
> header value, referer: <a href="https://jobs.oregonstate.edu/" target="_blank">https://jobs.oregonstate.edu/</a><br>
> [Wed Feb 01 17:08:29.924038 2023] [proxy_ajp:error] [pid 31685] [client<br>
> <a href="http://10.214.152.45:62219" target="_blank">10.214.152.45:62219</a>] AH00988: ajp_send_header: ajp_marshal_into_msgb<br>
> failed, referer: <a href="https://jobs.oregonstate.edu/" target="_blank">https://jobs.oregonstate.edu/</a><br>
> [Wed Feb 01 17:08:29.924073 2023] [proxy_ajp:error] [pid 31685]<br>
> (120001)APR does not understand this error code: [client<br>
> <a href="http://10.214.152.45:62219" target="_blank">10.214.152.45:62219</a>] AH00868: request failed to [::1]:8009 (localhost),<br>
> referer: <a href="https://jobs.oregonstate.edu/" target="_blank">https://jobs.oregonstate.edu/</a><br>
><br>
> From the Apache and IDP logs, this doesn't appear to be a loop. I don't<br>
> know why the header would be too big, either.<br>
><br>
> We're running this on Debian 10 with their latest apache2 and tomcat9<br>
> packages.<br>
><br>
> Is this the same error that you are seeing Jeff?<br>
><br>
> Thanks,<br>
> Andy<br>
><br>
> ------------------------------<br>
> *From:* users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Cantor, Scott<br>
> via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
> *Sent:* Thursday, February 2, 2023 7:27 AM<br>
> *To:* Jeff Chapin <<a href="mailto:jeff.chapin@uni.edu" target="_blank">jeff.chapin@uni.edu</a>><br>
> *Cc:* Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>>; Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
> *Subject:* Re: Documentation on 'e' and 's' in execution=eXsY<br>
><br>
> [This email originated from outside of OSU. Use caution with links and<br>
> attachments.]<br>
><br>
> > We have seen similar errors in the past when one of our SPs was trying to<br>
> > append a *VERY* long header, which was longer than the default header<br>
> length,<br>
> > so I may have jumped to a false conclusion.<br>
><br>
> My point is the SP might contaminate its own headers with cookies or what<br>
> have you, but it can't make the requests to the IdP "bigger" apart from via<br>
> the request URL or body. It can't "add headers" to the IdP requests.<br>
><br>
> As for the IdP, I am not aware of any scenario with loops that changes<br>
> much about the size of the requests. Cookies get replaced perhaps, but not<br>
> added.<br>
><br>
> Even a full login loop in local storage if it happened would replace the<br>
> SP record with the new one, the cache doesn't track > 1 session per SP.<br>
><br>
> -- Scott<br>
><br>
><br>
><br>
> --<br>
> For Consortium Member technical support, see<br>
> <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cmorgan%40oregonstate.edu%7C9b6e113a54f7486cd60108db0531fbd7%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638109484452455009%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=ea%2FV7cpPpViBUJiSYIxVp%2B80ZTyxg9R0lEE7%2FZA%2FRqg%3D&reserved=0" target="_blank">https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cmorgan%40oregonstate.edu%7C9b6e113a54f7486cd60108db0531fbd7%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638109484452455009%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=ea%2FV7cpPpViBUJiSYIxVp%2B80ZTyxg9R0lEE7%2FZA%2FRqg%3D&reserved=0</a><br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
><br>
<br>
<br>
-- <br>
<br>
Jeff Chapin,<br>
<br>
Panther eSports Adviser<br>
Systems/Applications Administrator<br>
ITS-IS, University of Northern Iowa<br>
Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a><br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20230202/1a0f9040/attachment-0001.htm" target="_blank">http://shibboleth.net/pipermail/users/attachments/20230202/1a0f9040/attachment-0001.htm</a>><br>
<br>
------------------------------<br>
<br>
Message: 11<br>
Date: Thu, 2 Feb 2023 14:23:10 -0500<br>
From: Mohamed Lrhazi <<a href="mailto:lrhazi@cua.edu" target="_blank">lrhazi@cua.edu</a>><br>
To: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Validation failure: Failed to resolve an encryption key<br>
Message-ID:<br>
<<a href="mailto:CAOm-VQ6W2RyV6OqKhBMo-Z3r_ygiL7o5iip9qKm_Sm7JvX2nsw@mail.gmail.com" target="_blank">CAOm-VQ6W2RyV6OqKhBMo-Z3r_ygiL7o5iip9qKm_Sm7JvX2nsw@mail.gmail.com</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
Hello,<br>
am trying to setup OIDC plugin, and testing using this sample app :<br>
<a href="https://github.com/curityio/example-python-openid-connect-client" target="_blank">https://github.com/curityio/example-python-openid-connect-client</a><br>
<br>
2023-02-02 13:43:06,648 - <a href="http://172.25.0.1/D5F65DA4F127D957EDB2BBFE68C7F0E6" target="_blank">172.25.0.1/D5F65DA4F127D957EDB2BBFE68C7F0E6</a> -<br>
> WARN<br>
> [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCEncryptionParameters:258]<br>
> - Profile Action PopulateOIDCEncryptionParameters: Resolver returned no<br>
> EncryptionParameters<br>
> 2023-02-02 13:43:06,647 - <a href="http://172.25.0.1/D5F65DA4F127D957EDB2BBFE68C7F0E6" target="_blank">172.25.0.1/D5F65DA4F127D957EDB2BBFE68C7F0E6</a> -<br>
> WARN [org.opensaml.xmlsec.impl.BasicEncryptionParametersResolver:243] -<br>
> Validation failure: Failed to resolve an encryption key<br>
> 2023-02-02 13:43:06,647 - <a href="http://172.25.0.1/D5F65DA4F127D957EDB2BBFE68C7F0E6" target="_blank">172.25.0.1/D5F65DA4F127D957EDB2BBFE68C7F0E6</a> -<br>
> DEBUG<br>
> [net.shibboleth.idp.plugin.oidc.op.security.impl.OIDCClientInformationEncryptionParametersResolver:226]<br>
> - No algorithm information in client information, falling back to default<br>
> configuration<br>
> 2023-02-02 13:43:06,647 - <a href="http://172.25.0.1/D5F65DA4F127D957EDB2BBFE68C7F0E6" target="_blank">172.25.0.1/D5F65DA4F127D957EDB2BBFE68C7F0E6</a> -<br>
> DEBUG<br>
> [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCEncryptionParameters:291]<br>
> - Profile Action PopulateOIDCEncryptionParameters: Adding OIDC client<br>
> information to resolution criteria for encryption algorithms<br>
> 2023-02-02 13:43:06,647 - <a href="http://172.25.0.1/D5F65DA4F127D957EDB2BBFE68C7F0E6" target="_blank">172.25.0.1/D5F65DA4F127D957EDB2BBFE68C7F0E6</a> -<br>
> DEBUG<br>
> [net.shibboleth.idp.plugin.oidc.op.profile.impl.PopulateOIDCEncryptionParameters:232]<br>
> - Profile Action PopulateOIDCEncryptionParameters: Resolving<br>
> EncryptionParameters for request object decryption<br>
<br>
<br>
<br>
What could cause this error?<br>
<br>
The config for this SP has these settings in it:<br>
<br>
<md:SPSSODescriptor protocolSupportEnumeration="<br>
> <a href="http://openid.net/specs/openid-connect-core-1_0.html" target="_blank">http://openid.net/specs/openid-connect-core-1_0.html</a>"><br>
> <md:Extensions><br>
> <oidcmd:OAuthRPExtensions<br>
> grant_types="authorization_code implicit refresh_token"<br>
> response_types="id_token code"<br>
> token_endpoint_auth_method="client_secret_post"<br>
> scopes="openid profile offline_access" /><br>
> </md:Extensions><br>
> <md:KeyDescriptor><br>
> <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#" target="_blank">http://www.w3.org/2000/09/xmldsig#</a>"><br>
><br>
> <oidcmd:ClientSecret>the-shared-secret-here</oidcmd:ClientSecret><br>
> </ds:KeyInfo><br>
> </md:KeyDescriptor><br>
><br>
> <md:NameIDFormat>urn:mace:shibboleth:metadata:oidc:1.0:nameid-format:public</md:NameIDFormat><br>
> <md:AssertionConsumerService<br>
> Binding="<a href="https://tools.ietf.org/html/rfc6749#section-3.1.2" target="_blank">https://tools.ietf.org/html/rfc6749#section-3.1.2</a><br>
> "<br>
> Location="<a href="https://localhost:5443/callback" target="_blank">https://localhost:5443/callback</a>"<br>
> index="1"/><br>
> </md:SPSSODescriptor><br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20230202/e0737798/attachment-0001.htm" target="_blank">http://shibboleth.net/pipermail/users/attachments/20230202/e0737798/attachment-0001.htm</a>><br>
<br>
------------------------------<br>
<br>
Message: 12<br>
Date: Fri, 3 Feb 2023 11:33:57 +0000<br>
From: Chris Reeves <<a href="mailto:chris.reeves@york.ac.uk" target="_blank">chris.reeves@york.ac.uk</a>><br>
To: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Re: Documentation on 'e' and 's' in execution=eXsY<br>
Message-ID: <<a href="mailto:20230203113357.GA1172306@itsusbeth5.york.ac.uk" target="_blank">20230203113357.GA1172306@itsusbeth5.york.ac.uk</a>><br>
Content-Type: text/plain; charset=us-ascii<br>
<br>
<br>
Hi both,<br>
<br>
The first thing that I would do is check what cookies are being set. Most<br>
problems that I've seen where headers have been to large have been down to<br>
cookies. While headers like User-Agent are user-controlled, your average user<br>
isn't going to touch these, but the Cookie header can grow simply by a user<br>
interacting with a lot of services in the same cookie domain.<br>
<br>
As an example, we have a lot of services that are hosted under <a href="http://www.york.ac.uk" target="_blank">www.york.ac.uk</a>,<br>
and the various proxy servers set cookies for session affinity. We very<br>
occasionally come across users who have interacted with too many of these, the<br>
Cookie header grows to large, and then we see these sorts of errors.<br>
<br>
Regards,<br>
Chris<br>
<br>
On Thu 02 Feb 2023 at 18:49:00 +0000, Jeff Chapin via users wrote:<br>
> It's very similar -- but we don't seem to have the AH03229:<br>
> ajp_msg_append_cvt_string(): BufferOverflowException portion. It looks like<br>
> we have the rest.<br>
> <br>
> On Thu, Feb 2, 2023 at 12:07 PM Morgan, Andrew J <<a href="mailto:morgan@oregonstate.edu" target="_blank">morgan@oregonstate.edu</a>><br>
> wrote:<br>
> <br>
> > I see an AJP error in my Apache logs several times a day as well. Here is<br>
> > an example from yesterday:<br>
> ><br>
> > [Wed Feb 01 17:08:29.923773 2023] [proxy_ajp:error] [pid 31685] AH03229:<br>
> > ajp_msg_append_cvt_string(): BufferOverflowException 4 770<br>
> > [Wed Feb 01 17:08:29.923979 2023] [proxy_ajp:error] [pid 31685] [client<br>
> > <a href="http://10.214.152.45:62219" target="_blank">10.214.152.45:62219</a>] AH00971: ajp_marshal_into_msgb: Error appending the<br>
> > header value, referer: <a href="https://jobs.oregonstate.edu/" target="_blank">https://jobs.oregonstate.edu/</a><br>
> > [Wed Feb 01 17:08:29.924038 2023] [proxy_ajp:error] [pid 31685] [client<br>
> > <a href="http://10.214.152.45:62219" target="_blank">10.214.152.45:62219</a>] AH00988: ajp_send_header: ajp_marshal_into_msgb<br>
> > failed, referer: <a href="https://jobs.oregonstate.edu/" target="_blank">https://jobs.oregonstate.edu/</a><br>
> > [Wed Feb 01 17:08:29.924073 2023] [proxy_ajp:error] [pid 31685]<br>
> > (120001)APR does not understand this error code: [client<br>
> > <a href="http://10.214.152.45:62219" target="_blank">10.214.152.45:62219</a>] AH00868: request failed to [::1]:8009 (localhost),<br>
> > referer: <a href="https://jobs.oregonstate.edu/" target="_blank">https://jobs.oregonstate.edu/</a><br>
> ><br>
> > From the Apache and IDP logs, this doesn't appear to be a loop. I don't<br>
> > know why the header would be too big, either.<br>
> ><br>
> > We're running this on Debian 10 with their latest apache2 and tomcat9<br>
> > packages.<br>
> ><br>
> > Is this the same error that you are seeing Jeff?<br>
> ><br>
> > Thanks,<br>
> > Andy<br>
> ><br>
> > ------------------------------<br>
> > *From:* users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Cantor, Scott<br>
> > via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
> > *Sent:* Thursday, February 2, 2023 7:27 AM<br>
> > *To:* Jeff Chapin <<a href="mailto:jeff.chapin@uni.edu" target="_blank">jeff.chapin@uni.edu</a>><br>
> > *Cc:* Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>>; Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
> > *Subject:* Re: Documentation on 'e' and 's' in execution=eXsY<br>
> ><br>
> > [This email originated from outside of OSU. Use caution with links and<br>
> > attachments.]<br>
> ><br>
> > > We have seen similar errors in the past when one of our SPs was trying to<br>
> > > append a *VERY* long header, which was longer than the default header<br>
> > length,<br>
> > > so I may have jumped to a false conclusion.<br>
> ><br>
> > My point is the SP might contaminate its own headers with cookies or what<br>
> > have you, but it can't make the requests to the IdP "bigger" apart from via<br>
> > the request URL or body. It can't "add headers" to the IdP requests.<br>
> ><br>
> > As for the IdP, I am not aware of any scenario with loops that changes<br>
> > much about the size of the requests. Cookies get replaced perhaps, but not<br>
> > added.<br>
> ><br>
> > Even a full login loop in local storage if it happened would replace the<br>
> > SP record with the new one, the cache doesn't track > 1 session per SP.<br>
> ><br>
> > -- Scott<br>
> ><br>
> ><br>
> ><br>
> > --<br>
> > For Consortium Member technical support, see<br>
> > <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cmorgan%40oregonstate.edu%7C9b6e113a54f7486cd60108db0531fbd7%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638109484452455009%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=ea%2FV7cpPpViBUJiSYIxVp%2B80ZTyxg9R0lEE7%2FZA%2FRqg%3D&reserved=0" target="_blank">https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cmorgan%40oregonstate.edu%7C9b6e113a54f7486cd60108db0531fbd7%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638109484452455009%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=ea%2FV7cpPpViBUJiSYIxVp%2B80ZTyxg9R0lEE7%2FZA%2FRqg%3D&reserved=0</a><br>
> > To unsubscribe from this list send an email to<br>
> > <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
> ><br>
> <br>
> <br>
> -- <br>
> <br>
> Jeff Chapin,<br>
> <br>
> Panther eSports Adviser<br>
> Systems/Applications Administrator<br>
> ITS-IS, University of Northern Iowa<br>
> Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a><br>
<br>
> -- <br>
> For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
<br>
------------------------------<br>
<br>
Subject: Digest Footer<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
------------------------------<br>
<br>
End of users Digest, Vol 140, Issue 3<br>
*************************************<br>
</div>
</blockquote></div></div>