<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"Noto Sans";}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
mso-fareast-language:EN-US;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;
mso-fareast-language:EN-US;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:70.85pt 70.85pt 2.0cm 70.85pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="DE" link="#0563C1" vlink="#954F72" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span lang="EN-US">Hi all,<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">I’m trying to setup a shibboleth server as federation gateway and protocol transitioning server.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">Essentially its: local app -> shib-server (/w open-id) -> Federation IDPs<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">I got to the point, that the authentication will be triggered, I choose the IDP I want to use via WAYF (or Discovery) and got a SAML Token, that can be decoded back in my Federation-Gateway (or IDP Proxy or whatever you
want to call it).<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">There I’m stuck and found the following debug messages after which I get the error message:<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [org.opensaml.saml.saml2.assertion.impl.AssertionValidationSupport:65] - Evaluating SubjectConfirmationData/@Address value of: 134.93.179.74<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [org.opensaml.saml.saml2.assertion.impl.AssertionValidationSupport:79] - SubjectConfirmationData/@Address was resolved to addresses: [/134.93.179.74]<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [org.opensaml.saml.saml2.assertion.impl.AssertionValidationSupport:108] - Failed to match SubjectConfirmationData/@Address to any supplied valid addresses: [/2001:4c80:40:4b3:b25c:daff:fe34:1495]<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [org.opensaml.saml.saml2.assertion.SAML20AssertionValidator:896] - No subject confirmation methods were met for assertion with ID '_edc867b30d74a4e18d42859b28dfff91'<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [org.opensaml.saml.saml2.profile.impl.ValidateAssertions:299] - Profile Action ValidateAssertions: Assertion validation result was: INVALID<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">INFO [org.opensaml.saml.saml2.profile.impl.ValidateAssertions:301] - Profile Action ValidateAssertions: Assertion validation failure msg was: No subject confirmation methods were met for assertion with ID '_edc867b30d74a4e18d42859b28dfff91'<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.ProcessAssertionsForAuthentication:217] - Profile Action ProcessAssertionsForAuthentication: Removing 1 non-valid Assertions from Response<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">INFO [net.shibboleth.idp.saml.saml2.profile.impl.ProcessAssertionsForAuthentication:228] - Profile Action ProcessAssertionsForAuthentication: No valid SAML Assertions suitable for authentication were found<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">NFO [Shibboleth-Audit.SSO:338] - 2001:4c80:40:4b3:b25c:daff:fe34:1495||2023-03-15T09:06:36.863292Z||https://shib.uni-mainz.de/idp/shibboleth||||||||false||Redirect||InvalidCredentials||||Mozilla/5.0 (Windows NT 10.0;
Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36 Edg/111.0.1661.41<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">INFO [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:142] - Profile Action SelectAuthenticationFlow: Moving incomplete flow authn/SAML to intermediate set<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:274] - Profile Action SelectAuthenticationFlow: No specific Principals requested<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:312] - Profile Action SelectAuthenticationFlow: No usable active results available, selecting an inactive flow<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">INFO [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:316] - Profile Action SelectAuthenticationFlow: No potential flows left to choose from, authentication failed<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractBuildErrorResponseFromEvent:159] - Profile Action BuildAuthenticationErrorResponseFromEvent: No mapped event found for NoPotentialFlow, creating general invalid_request<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [net.shibboleth.idp.plugin.oidc.op.profile.impl.AbstractBuildErrorResponseFromEvent:166] - Profile Action BuildAuthenticationErrorResponseFromEvent: ErrorResponse successfully set as the outbound message<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">WARN [DEPRECATED:128] - Java class method 'setHttpServletResponse', (net.shibboleth.idp.plugin.oidc.op.encoding.impl.NimbusResponseEncoder): This will be removed in the next major version of this software; replacement
is setHttpServletResponseSupplier<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">INFO [Shibboleth-Audit.OIDC.SSO:338] - 2001:4c80:40:4b3:b25c:daff:fe34:1495|2023-03-15T09:06:35.315488Z,2023-03-15T09:06:32.121212Z|2023-03-15T09:06:36.933848Z||OIDC-test-client||||||||||AuthenticationRequest|AuthenticationErrorResponse|NoPotentialFlow||||Mozilla/5.0
(Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36 Edg/111.0.1661.41<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">DEBUG [net.shibboleth.idp.profile.impl.RecordResponseComplete:89] - Profile Action RecordResponseComplete: Record response complete<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">The IPAddressees above both resolve to the same (my browser) machine – so this looks like a problem with IPAddress resolving to me<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE">Thomas Ottenhus (geb. Glatzer)<o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE">Zentrum für Datenverarbeitung (ZDV)</span></b><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE">Leiter Softwareentwicklung<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE">Johannes Gutenberg-Universität Mainz<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE">Anselm-Franz-von-Bentzel-Weg 12, 55128 Mainz<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE">Tel: +49 6131 39 26487<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE"><a href="mailto:ottenhus@uni-mainz.de"><span style="color:#636363;text-decoration:none">ottenhus@uni-mainz.de</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE"><a href="mailto:zdvdev@uni-mainz.de"><span style="color:#636363;text-decoration:none">zdvdev@uni-mainz.de</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Noto Sans",sans-serif;color:#636363;mso-fareast-language:DE"><a href="https://www.zdv.uni-mainz.de/"><span style="color:#636363;text-decoration:none">https://www.zdv.uni-mainz.de</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>