<div dir="ltr"><div dir="ltr">Thanks very much...  <input name="virtru-metadata" type="hidden" value="{"email-policy":{"disableCopyPaste":false,"disablePrint":false,"disableForwarding":false,"enableNoauth":false,"expandedWatermarking":false,"expires":false,"sms":false,"expirationNum":1,"expirationUnit":"days","isManaged":false,"persistentProtection":false},"attachments":{},"compose-id":"28","compose-window":{"secure":false}}"><div>On the chance it might be something obvious, here is what I am seeing.  (otherwise, I'll open a ticket)</div><div><br>I first log in to the normal SP.  Password ok.  It then goes to the DefaultDuoOIDC Duo and is approved, with the default principal '<a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a>'.  Good.</div><div>Then I try to SSO to the Special SP, which should decide to use the Level2DuoOIDC '<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a>'   and go to Duo again.  But it fails instead.</div><div><br></div><div>The IDP first says the result from the DefaultDuo is not usable:</div><div>     "Active result for flow authn/MFA not usable, ignoring."  </div><div>But then it says it's reusing it:</div><div>     "Reusing active result for flow authn/DuoOIDC"</div><div>And then says it doesn't satisfy the request:</div><div>     "Authentication result for flow authn/MFA did not satisfy the request"<br><br><div><b>Here is the log from the SSO:</b></div><div><br></div><div>DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:190] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeAuthenticationContext:239] - Profile Action InitializeAuthenticationContext: AuthnRequest did not contain Scoping, nothing to do - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeAuthenticationContext:222] - Profile Action InitializeAuthenticationContext: Created authentication context: AuthenticationContext{initiationInstant=2024-09-19T21:59:02.124556Z, isPassive=false, forceAuthn=false, requiredName=null, hintedName=null, maxAge=null, potentialFlows=[], activeResults=[], attemptedFlow=null, signaledFlowId=null, authenticationStateMap={}, resultCacheable=true, authenticationResult=null, completionInstant=null} - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.ProcessRequestedAuthnContext:167] - Profile Action ProcessRequestedAuthnContext: AuthnRequest did not contain a RequestedAuthnContext, nothing to do - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.PopulateAuthenticationContext:213] - Profile Action PopulateAuthenticationContext: Installed 1 potential authentication flows into AuthenticationContext - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.session.impl.StorageBackedSessionManager:813] - Performing primary lookup on session ID 94a4c1e8119de287fef5a4a7cec473673631807bc0b0331b5f87f6a8e2de240d - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.session.impl.StorageBackedIdPSession:88] - Updating expiration of primary record for session 94a4c1e8119de287fef5a4a7cec473673631807bc0b0331b5f87f6a8e2de240d to 2024-09-20T06:59:02.128223Z - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.session.impl.StorageBackedIdPSession:540] - Loading AuthenticationResult for flow authn/MFA in session 94a4c1e8119de287fef5a4a7cec473673631807bc0b0331b5f87f6a8e2de240d - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.session.impl.ExtractActiveAuthenticationResults:134] - Profile Action ExtractActiveAuthenticationResults: Authentication result authn/MFA is active, copying from session - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.InitializeRequestedPrincipalContext:163] - Profile Action InitializeRequestedPrincipalContext: Established RequestedPrincipalContext with 1 methods - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByForcedAuthn:57] - Profile Action FilterFlowsByForcedAuthn: Request does not have forced authentication requirement, nothing to do - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.FilterFlowsByNonBrowserSupport:57] - Profile Action FilterFlowsByNonBrowserSupport: Request does not have non-browser requirement, nothing to do - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:401] - Profile Action SelectAuthenticationFlow: Specific principals requested with 'exact' operator: [AuthnContextClassRefPrincipal{authnContextClassRef=<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a>}] - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:511] - Profile Action SelectAuthenticationFlow: Checking for an inactive flow or active result compatible with operator 'exact' and principal '<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a>' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.principal.PrincipalEvalPredicateFactoryRegistry:126] - Registry located predicate factory of type 'net.shibboleth.idp.authn.principal.impl.ExactPrincipalEvalPredicateFactory' for principal type 'class net.shibboleth.idp.saml.authn.principal.AuthnContextClassRefPrincipal' and operator 'exact' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:526] - Profile Action SelectAuthenticationFlow: Active result for flow authn/MFA not usable, ignoring - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.SelectAuthenticationFlow:369] - Profile Action SelectAuthenticationFlow: Selecting inactive authentication flow authn/MFA - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.PopulateMultiFactorAuthenticationContext:163] - Profile Action PopulateMultiFactorAuthenticationContext: 2 active result(s) extracted for possible reuse: [authn/Password, authn/DuoOIDC] - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:212] - Profile Action TransitionMultiFactorAuthentication: Applying MFA transition rule to determine initial state - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:226] - Profile Action TransitionMultiFactorAuthentication: MFA flow transition after 'proceed' event to 'authn/Password' flow - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:276] - Profile Action TransitionMultiFactorAuthentication: Reusing active result for flow authn/Password - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:214] - Profile Action TransitionMultiFactorAuthentication: Applying MFA transition rule to exit state 'authn/Password' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.principal.PrincipalEvalPredicateFactoryRegistry:126] - Registry located predicate factory of type 'net.shibboleth.idp.authn.principal.impl.ExactPrincipalEvalPredicateFactory' for principal type 'class net.shibboleth.idp.saml.authn.principal.AuthnContextClassRefPrincipal' and operator 'exact' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.principal.PrincipalEvalPredicateFactoryRegistry:126] - Registry located predicate factory of type 'net.shibboleth.idp.authn.principal.impl.ExactPrincipalEvalPredicateFactory' for principal type 'class net.shibboleth.idp.saml.authn.principal.AuthnContextClassRefPrincipal' and operator 'exact' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:226] - Profile Action TransitionMultiFactorAuthentication: MFA flow transition after 'proceed' event to 'authn/DuoOIDC' flow - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:276] - Profile Action TransitionMultiFactorAuthentication: Reusing active result for flow authn/DuoOIDC - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:214] - Profile Action TransitionMultiFactorAuthentication: Applying MFA transition rule to exit state 'authn/DuoOIDC' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.TransitionMultiFactorAuthentication:231] - Profile Action TransitionMultiFactorAuthentication: MFA flow completing with event 'proceed' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.FinalizeMultiFactorAuthentication:192] - Profile Action FinalizeMultiFactorAuthentication: MFA complete, producing merged result - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.PopulateSubjectCanonicalizationContext:75] - Profile Action PopulateSubjectCanonicalizationContext: Installing 2 canonicalization flows into SubjectCanonicalizationContext - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:100] - Profile Action SelectSubjectCanonicalizationFlow: Checking canonicalization flow c14n/x500 for applicability... - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:106] - Profile Action SelectSubjectCanonicalizationFlow: Canonicalization flow c14n/x500 was not applicable: Neither a single X509Certificate nor X500Principal were found - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:100] - Profile Action SelectSubjectCanonicalizationFlow: Checking canonicalization flow c14n/simple for applicability... - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.SelectSubjectCanonicalizationFlow:83] - Profile Action SelectSubjectCanonicalizationFlow: Selecting canonicalization flow c14n/simple - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction:221] - Profile Action SimpleSubjectCanonicalization: trimming whitespace of input string 'theuserid' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.session.impl.DetectIdentitySwitch:168] - Profile Action DetectIdentitySwitch: Identities from session and new authentication result match, nothing to do - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.FinalizeAuthentication:116] - Profile Action FinalizeAuthentication: Canonical principal name was established as 'theuserid' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.impl.FinalizeAuthentication:229] - Profile Action FinalizeAuthentication: Checking result for compatibility with operator 'exact' and principal '<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a>' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [net.shibboleth.idp.authn.principal.PrincipalEvalPredicateFactoryRegistry:126] - Registry located predicate factory of type 'net.shibboleth.idp.authn.principal.impl.ExactPrincipalEvalPredicateFactory' for principal type 'class net.shibboleth.idp.saml.authn.principal.AuthnContextClassRefPrincipal' and operator 'exact' - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>WARN [net.shibboleth.idp.authn.impl.FinalizeAuthentication:164] - Profile Action FinalizeAuthentication: Authentication result for flow authn/MFA did not satisfy the request - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>WARN [org.opensaml.profile.action.impl.LogEvent:101] - A non-proceed event occurred while processing the request: RequestUnsupported - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]<br>DEBUG [org.opensaml.saml.common.profile.logic.DefaultLocalErrorPredicate:172] - Error event RequestUnsupported will be handled with response - [node01uk2mhrhajtpqir5jq8wum6273] - [99.99.99.99]</div><div><br></div><div>----------------------------------------------------------------------------------------</div><div><br></div><div>Settings:</div><div><br></div><b>authn.properties</b><br># Unset if you have advanced Duo integrations with individualized Principals<br>idp.authn.Duo.addDefaultPrincipals = false<br><br>idp.authn.Duo.supportedPrincipals = \<br>    saml2/<a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a>, \<br>    saml2/<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a>, \<br>    saml1/<a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a>, \<br>    saml1/<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a><br>    <br>idp.authn.MFA.supportedPrincipals = \<br>    saml2/urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport, \<br>    saml2/urn:oasis:names:tc:SAML:2.0:ac:classes:Password, \<br>    saml2/<a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a>, \<br>    saml2/<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a>, \<br>    saml1/urn:oasis:names:tc:SAML:1.0:am:password, \<br>    saml1/<a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a>, \<br>    saml1/<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a><br>    <br><b>duo-oidc.properties</b><br>idp.authn.DuoOIDC.supportedPrincipals = \<br>    saml2/<a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a>, \<br>    saml2/<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a>, \<br>    saml1/<a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a>, \<br>    saml1/<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a><br>    <br>idp.authn.DuoOIDC.addDefaultPrincipals = false<br><br><b>duo-oidc-authn-config.xml</b><br>      <bean id="DefaultDuoOIDC" parent="shibboleth.authn.DuoOIDC.DuoIntegration"<br>            p:APIHost="%{idp.duo.oidc.apiHost:none}"<br>            p:clientId="%{idp.duo.oidc.clientId:none}" <br>            p:secretKey="%{idp.duo.oidc.secretKey:none}"><br>        <property name="supportedPrincipals"><br>          <list><br>            <bean parent="shibboleth.SAML2AuthnContextClassRef"<br>              c:classRef="<a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a>" /><br>            <bean parent="shibboleth.SAML1AuthenticationMethod"<br>              c:method="<a href="https://refeds.org/profile/mfa" target="_blank">https://refeds.org/profile/mfa</a>" /><br>          </list><br>        </property><br>      </bean><br><br>      <bean id="Level2DuoOIDC" parent="shibboleth.authn.DuoOIDC.DuoIntegration"<br>            p:APIHost="%{idp.duo2.oidc.apiHost:none}"<br>            p:clientId="%{idp.duo2.oidc.clientId:none}" <br>            p:secretKey="%{idp.duo2.oidc.secretKey:none}"><br>        <property name="supportedPrincipals"><br>          <list><br>            <bean parent="shibboleth.SAML2AuthnContextClassRef"<br>              c:classRef="<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a>" /><br>            <bean parent="shibboleth.SAML1AuthenticationMethod"<br>              c:method="<a href="https://refeds.org/profile/mfa-level2" target="_blank">https://refeds.org/profile/mfa-level2</a>" /><br>          </list><br>        </property><br>      </bean><br><br>      <util:list id="DuoIntegrationList"><br>        <ref bean="DefaultDuoOIDC" /><br>        <ref bean="Level2DuoOIDC" /><br>      </util:list><br><br>    <bean id="shibboleth.authn.DuoOIDC.DuoIntegrationStrategy" parent="shibboleth.ContextFunctions.Scripted"<br>    ...same script as in the example...<br></div><div><br></div><div></div></div><br><div class="gmail_quote" style=""><div dir="ltr" class="gmail_attr">On Thu, Sep 19, 2024 at 11:52 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> I have learned that the order of the DuoIntegrationList is very<br>
> important.  In the log, I can see the IDP is searching for my<br>
> SpecialDuo integration, but it's still getting lost when doing<br>
> SSO and sorting thru results.<br>
<br>
The order matters because the script that derives the one to use is built in a specific way to iterate over them looking for the first match, on the assumption that you want more strict rules to be used only when necessary. If there is no order that makes sense and they won't sort of subset each other, the whole approach probably isn't applicable.<br>
<br>
> Does anyone know of any other documentation specifically<br>
> for the DuoOIDC version of this functionality? Or a newer<br>
> description?<br>
<br>
I didn't do a V5 article but there's not any difference apart from it would be a Universal Prompt one to start with. It's largely s/Duo/DuoOIDC all over the place. The Duo plugin has general docs on the multiple integration support, I don't know that anything is missing.<br>
<br>
The REFEDS example is just a specific application of the feature that is usually similar to what people tend to do on campus.<br>
<br>
> Did anyone run into issues/pitfalls implementing this that<br>
> might help me? anything specific to DuoOIDC besides the<br>
> aforementioned bug?<br>
<br>
I don't think the bug even exists anymore, but I don't know exactly when it was fixed and it doesn't hurt anything.<br>
<br>
There's no way to really answer this, you have to use the logs to actually determine what specifically it's doing wrong, and you never actually said. There are all sorts of general issues related to the MFA flow being defined correctly, complications like user-specific policies getting in the way. It just depends what it's actually doing, but if it's picking an existing result when it shouldn't, that means the principal set just isn't right.<br>
<br>
Brown is a member, I would advise a support ticket so that logs can be included and a more detailed description of the problem provided.<br>
<br>
-- Scott<br>
<br>
<br>
</blockquote></div>
</div>