<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:x="urn:schemas-microsoft-com:office:excel" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if gte mso 9]><xml>
<w:WordDocument>
<w:DontUseAdvancedTypographyReadingMail/>
<w:DontUseJustificationAdvancedTypographyReadingMail/>
<w:DontUseHyphenationAdvancedTypographyReadingMail/>
</w:WordDocument>
</xml><![endif]--><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Aptos;}
@font-face
{font-family:Corbel;
panose-1:2 11 5 3 2 2 4 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:12.0pt;
font-family:"Aptos",sans-serif;
mso-ligatures:standardcontextual;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#467886;
text-decoration:underline;}
span.EmailStyle20
{mso-style-type:personal-reply;
font-family:"Aptos",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;
mso-ligatures:none;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#467886" vlink="#96607D" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Thanks for this, Phil. FWIW, even after adding:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><logger name="net.shibboleth.oidc.security" level="DEBUG"/><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">to logback.xml, I still don’t see any of the events in the logs that you described. I did see the outbound request in the logs with the acr_values HTTP parameter and the appropriate value of c1 getting passed to Entra. But I can’t see what’s
coming back in the tokens. It’s not getting logged.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I’m not sure, however, if that’s going to help me anyway in this case. Wondering if anyone is successfully doing OIDC with ACR signaling a Shib IdP proxying to Entra with OIDC.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">The current issue is that Microsoft doesn’t seem to be following the spec, as shocking as that may be.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Entra doesn’t have claims_parameter_supported present, let alone set to true, in their OP metadata for my tenant. If they did, we found examples on the web where people are passing in a claims parameter in the authorize request for acr
marked as essential. They accept it, but their metadata doesn’t advertise it, and thus Shibboleth doesn’t try because the spec says not to.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">We’re still struggling to see why Entra doesn’t seem to be trying to satisfy the request sent in using the acr_values query parameter, but even if it would, that’s not going to help us since that’s an optional request, anyway. If our intent
is to force MFA and the user isn’t eligible for MFA, Entra will just return the user without satisfying MFA and obviously without the acr claim in the response.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I’d welcome any thoughts or recipes from anyone who got this working.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal">Keith<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;mso-ligatures:none">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;mso-ligatures:none"> users <users-bounces@shibboleth.net>
<b>On Behalf Of </b>Philip Smart via users<br>
<b>Sent:</b> Friday, March 6, 2026 11:09 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Philip Smart <Philip.Smart@jisc.ac.uk><br>
<b>Subject:</b> Re: Debugging SAML to OIDC ACR proxying<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span lang="EN-GB">Hi Keith<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-GB">| Simple question: what logging class can I turn up that would show me the ACR being sent to Microsoft in the request?
<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">The OIDC/OAuth message encoders should show the parameters of the request if you set idp.loglevel.messages to DEBUG and find the log line with category [PROTOCOL_MESSAGE.OAUTH2]. If the OP supports the claims parameter,
the ACR values should be inside the claims parameter; else, they will be inside the acr_values parameter. If you use a request object, the ACR values will be inside the request object, and you will need to decode the base64URL encoded JWT from the request
parameter to find them. <o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-GB">| And what class would show me what's coming back?
<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">Sadly, the same logging does not exist on the decoders, but it should [1]. However, for now, there are less elegant ways of logging the raw id_token by using a logger for the category net.shibboleth.oidc.security and
setting it to DEBUG. In particular, the BaseSignedJWTTrustEngine should log the base64url encoded JWT, which you can decode.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">Let me know how you get on, it is possible the RP is not behaving correctly, and we will need to fix something.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">Phil<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">[1] <a href="https://urldefense.com/v3/__https:/shibboleth.atlassian.net/browse/JCOMOIDC-158__;!!DZ3fjg!7lIl8qRcVfqfdK1W9RBiFbbJlS7fQrm35ZFr0HW0WPMrBkeSM2IEOsPtqMO5tuo3pSpzSx5FrP5yHjyGfU0J$">
https://shibboleth.atlassian.net/browse/JCOMOIDC-158</a><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:7.5pt;font-family:"Corbel",sans-serif;mso-ligatures:none"><o:p> </o:p></span></p>
<p style="margin-bottom:12.0pt"><span lang="EN-GB" style="font-size:7.5pt;font-family:"Corbel",sans-serif">Jisc is a registered charity (in England and Wales under charity number 1149740; in Scotland under charity number SC053607) and a company limited by guarantee
registered in England under company number 05747339, VAT number GB 197 0632 86. Jisc's registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<o:p></o:p></span></p>
<p style="margin-bottom:12.0pt"><span lang="EN-GB" style="font-size:7.5pt;font-family:"Corbel",sans-serif">Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 02881024,
VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<o:p></o:p></span></p>
<p><span lang="EN-GB" style="font-size:7.5pt;font-family:"Corbel",sans-serif">For more details on how Jisc handles your data see our privacy notice here:
<a href="https://urldefense.com/v3/__https:/www.jisc.ac.uk/website/privacy-notice__;!!DZ3fjg!7lIl8qRcVfqfdK1W9RBiFbbJlS7fQrm35ZFr0HW0WPMrBkeSM2IEOsPtqMO5tuo3pSpzSx5FrP5yHpWDiuyf$">
https://www.jisc.ac.uk/website/privacy-notice</a><o:p></o:p></span></p>
</div>
</body>
</html>