<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
font-size:11.0pt;
font-family:"Aptos",sans-serif;
mso-fareast-language:EN-US;}
span.EmailStyle18
{mso-style-type:personal-compose;
font-family:"Aptos",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:11.0pt;
mso-ligatures:none;
mso-fareast-language:EN-US;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-CA" link="#467886" vlink="#96607D" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Hello,<o:p></o:p></p>
<p class="MsoNormal">When I login to the application URL I am successfully redirected to the IDP portal and able to login with out issue, however once I have logged in and it sends me back to the application I get the above error<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I am relatively new to Shibboleth, can I know where to start checking?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Here are some sample from the log<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: extracting issuer from SAML 2.0 protocol message<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: message from (sso-portal-sit.fst.lntinfotech.com)<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: searching metadata for message issuer...<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.MessageDecoder.SAML2 [2] [default]: recovered request/response correlation value (_f977128e1bfe7ae6435e3aaafa2ebe0e)<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: evaluating message flow policy (correlation off, replay checking on, expiration 60)<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: ignoring InResponseTo, correlation checking is disabled<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: evaluating message flow policy (correlation off, replay checking on, expiration 60)<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2] [default]: ignoring InResponseTo, correlation checking is disabled<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [2] [default]: ignoring InResponseTo, correlation checking is disabled<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [2] [default]: assertion satisfied bearer confirmation requirements<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 WARN Shibboleth.SSO.SAML2 [2] [default]: detected a problem with assertion: Unable to establish security of incoming assertion.<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 WARN Shibboleth.SSO.SAML2 [2] [default]: error processing incoming assertion: Unable to establish security of incoming assertion.<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1] [default]: validating input<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.MessageEncoder.SAML2 [1] [default]: tracking request (_253d5c2b70eab4c93dfe0e0bcf7a299d) against RelayState token (ss:mem:50d61be8b239b85b525dd1fb65ee4e6f9331b671f639d6989e0a03b05e56663c)<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1] [default]: marshalling, deflating, base64-encoding the message<o:p></o:p></p>
<p class="MsoNormal">2024-09-26 10:50:12 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1] [default]: marshalled message:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<br>
<hr>
<font face="Arial" color="Black" size="3"><br>
The contents of this e-mail and any attachment(s) may contain confidential or privileged information for the intended recipient(s). Unintended recipients are prohibited from taking action on the basis of information in this e-mail and using or disseminating
the information, and must notify the sender and delete it from their system. LTIMindtree will not accept responsibility or liability for the accuracy or completeness of, or the presence of any virus or disabling code in this e-mail.<br>
</font>
</body>
</html>