<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi,</div>
<div class="elementToProof" style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
We have IDP v4.3.1 + CAS integration. It has been all working fine for years.</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
However, we recently discovered something which is unusual. It is about wrong Entity ID being passed in conversation state. Here is what happened</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<ol start="1" data-editing-info="{"applyListStyleFromLevel":false,"orderedStyleType":1}" style="text-align: left; margin-top: 0px; margin-bottom: 0px; list-style-type: decimal; flex-direction: column; display: flex;">
<li style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); align-self: start; margin: 0px;">
<div class="elementToProof" role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
Users try to access Service Provider/application  A </div>
<div role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
<br>
</div>
</li><li style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); align-self: start; margin: 0px;">
<div class="elementToProof" role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
The request is redirected to IDP with AuthnRequest having issuer with EntityID=applicationA</div>
<div class="elementToProof" role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
2.1 POST <a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO" id="OWAcf4971ff-e0bd-3b04-031e-d2c8031befb9" class="OWAAutoLink">
https://<<IDPSERVER>>/idp/profile/SAML2/POST/SSO</a> </div>
<div role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
<br>
</div>
</li><li style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); align-self: start; margin: 0px;">
<div class="elementToProof" role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
IDP then redirects the request to CAS for authentication with following flows</div>
<div role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
<br>
</div>
<div class="elementToProof" role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
3.1 GET <a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO?execution=e1s1" id="OWA11891714-770c-7932-14c3-8700f65c5a69" class="OWAAutoLink">
https://</a><a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO" id="OWAe8c7ec73-a4dc-4413-99a0-e1d5eeb35f38" class="OWAAutoLink"><<IDPSERVER>></a><a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO?execution=e1s1" id="OWA42871135-4c70-0d53-0a41-a8a1473ee692" class="OWAAutoLink">/idp/profile/SAML2/POST/SSO?execution=e1s1</a></div>
<div class="elementToProof" role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
3.2 POST <a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO?execution=e1s1" id="OWA1c422675-6ec1-713c-6e3f-e128d57c48d6" class="OWAAutoLink">
https://</a><a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO" id="OWAbe8cd010-0bfe-390c-0759-4dfb12ae1dc9" class="OWAAutoLink"><<IDPSERVER>></a><a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO?execution=e1s1" id="OWA63bc6c25-2144-6a10-758c-5c57dc953c04" class="OWAAutoLink">/idp/profile/SAML2/POST/SSO?execution=e1s1</a></div>
<div class="elementToProof" role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
3.3 GET <a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO?execution=e1s2" id="OWA29bac235-b010-abbe-2603-8160e20c4d92" class="OWAAutoLink">
https://</a><a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO" id="OWAf090f64d-06f1-dd67-ba39-42cba61cff50" class="OWAAutoLink"><<IDPSERVER>></a><a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO?execution=e1s2" id="OWAd27528f4-823d-4117-abb4-75803bc4c5f5" class="OWAAutoLink">/idp/profile/SAML2/POST/SSO?execution=e1s2</a>,
 then redirect to next request</div>
<div class="elementToProof" role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
3.4 GET <a href="https://idpweb1.vu.edu.au/idp/Authn/External?conversation=e1s2" id="OWA7782446a-3f72-70b4-4598-0306409c1f49" class="OWAAutoLink">
https://</a><a href="https://idpweb1.vu.edu.au/idp/profile/SAML2/POST/SSO" id="OWA92317e63-0c09-57e1-9507-26e1af1a02df" class="OWAAutoLink"><<IDPSERVER>></a><a href="https://idpweb1.vu.edu.au/idp/Authn/External?conversation=e1s2" id="OWA0333408d-4bf9-e39e-f3e6-fd1162da71e2" class="OWAAutoLink">/idp/Authn/External?conversation=e1s2</a> ,
 then redirect to next request</div>
<div class="elementToProof" role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
3.5 GET <a href="https://login.vu.edu.au/cas/login?service=https%3A%2F%2Fidpweb1.vu.edu.au%2Fidp%2FAuthn%2FExternal%3Fconversation%3De1s2&entityId=https%3A%2F%2Fmyvu.edu.au%2Fmyvu" id="OWA3f6fd00f-1f38-2141-e6bb-a3fa0378e1f5" class="OWAAutoLink">
https://<<CASSERVER>>/cas/login?service=https://<<IDPSERVER>>/idp/Authn/External?/conversation=e1s2&entityId=</a>applicationB/C/D</div>
<div role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
<br>
</div>
<div class="elementToProof" role="presentation" style="text-align: left; text-indent: 0px; line-height: 1.4; margin-top: 0px; margin-bottom: 0px;">
At step 3.5 we found the entity ID passed to CAS from IDP ( step 3.4) appears to be from random other SPs configured on IDP server e.g. applicationA, application B, applicationC etc.  We expect the entityID=applicationA, but most of the time it doesn't. As
 a result of incorrect entity ID passed to CAS, the CAS login doesn't work as expected.</div>
</li></ol>
<div style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
We have tried in private window/incognito mode and clear browser histories, but it doesn't help. </div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Could anyone please advise what could cause the issue and how to resolve it? </div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks,</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Pinate</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; line-height: 1.4; margin: 0px; font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
</body>
</html>