cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Stefan Winter <address@concealed>
- To: "Fenwick, David" <address@concealed>, "address@concealed" <address@concealed>
- Subject: Re: [[cat-users]] Unhandled exception after idp authentication
- Date: Mon, 28 Jan 2019 10:25:07 +0100
Hi,
> Can you point us in the right direction where we need to change this
> configuration on our idp server, it is running Centos6. Do we need to
> substitute the NameQualifier and WAYF-DK-some_value (highlited parts )
> below for anything unique to us? We are a bit lost how to fix this but
> I am desperate to get on the CAT admin portal. We do use OpenAthens for
> other stuff as well and do not want to impact any live services.
Sorry, but you are now asking a deeply SAML-related question. This is
not the area of expertise of this mailing list. We also know nothing
about your SAML deployment or your national SAML federation's configuration.
You really need to ask your SAML federation operator.
What strikes me is that your mail domain suggests you are in the UK
(where SAML questions are with JISC) but the NameIDs you pasted here are
some connected to Denmark. The error is likely somewhere near this
discrepancy, but don't talk to us about it; we know nothing about
nothing in regards to SAML :-)
We just consume valid SAML assertions once we get them. Yours didn't get
that far.
Stefan
>
>
>
>
>
> <saml:Attribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10"
> NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
>
>
>
> <saml:AttributeValue>
>
>
>
> <saml:NameID
> NameQualifier="https://birk.wayf.dk/birk.php/wayf.itu.dk/saml2/idp/metadata.php"
> SPNameQualifier="https://monitor.eduroam.org/sp/module.php/saml/sp/metadata.php/default-sp"
> Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent">WAYF-DK-some_value</saml:NameID>
>
>
>
> </saml:AttributeValue>
>
>
>
> </saml:Attribute>
>
>
>
>
>
> David Fenwick
>
> *Network Administrator*
>
> 01784276664
> Royal Holloway, University of London
> Egham, Surrey, TW20 0EX
>
>
>
> *From:*Fenwick, David
> *Sent:* 18 December 2018 08:28
> *To:* 'address@concealed' <address@concealed
> <mailto:address@concealed>>
> *Subject:* Unhandled exception after idp authentication
>
>
>
> Hi Support,
>
> I’m having issues getting onto the cat site, I have not been on previously.
>
>
>
> I choose my organisation, get redirected to an OpenAthens login for my
> org, login and get redirected to
> https://monitor.eduroam.org/sp/module.php/saml/sp/saml2-acs.php/default-sp
>
> Where I get a unhandled exception page below. Can you help please J .
>
>
>
>
>
> *Debug information*
>
> The debug information below may be of interest to the administrator /
> help desk:
>
> SimpleSAML_Error_Error: UNHANDLEDEXCEPTION
>
> Backtrace:
>
> 1 www/_include.php:45 (SimpleSAML_exception_handler)
>
> 0 [builtin] (N/A)
>
> Caused by: SAML2\Exception\RuntimeException: A
> "urn:mace:dir:attribute-def:eduPersonTargetedID" (EPTI) attribute value
> must be a NameID, none found for value no. "0"
>
> Backtrace:
>
> 8 vendor/simplesamlphp/saml2/src/SAML2/Assertion.php:558
> (SAML2\Assertion::parseAttributeValue)
>
> 7 vendor/simplesamlphp/saml2/src/SAML2/Assertion.php:540
> (SAML2\Assertion::parseAttributes)
>
> 6 vendor/simplesamlphp/saml2/src/SAML2/Assertion.php:298
> (SAML2\Assertion::__construct)
>
> 5 vendor/simplesamlphp/saml2/src/SAML2/EncryptedAssertion.php:97
> (SAML2\EncryptedAssertion::getAssertion)
>
> 4 modules/saml/lib/Message.php:398 (sspmod_saml_Message::decryptAssertion)
>
> 3 modules/saml/lib/Message.php:611 (sspmod_saml_Message::processAssertion)
>
> 2 modules/saml/lib/Message.php:578 (sspmod_saml_Message::processResponse)
>
> 1 modules/saml/www/sp/saml2-acs.php:129 (require)
>
> 0 www/module.php:135 (N/A)
>
>
>
>
>
>
>
> David Fenwick
>
> *Network Administrator*
>
> 01784276664
> Royal Holloway, University of London
> Egham, Surrey, TW20 0EX
>
>
>
> To unsubscribe, send this message:
> mailto:address@concealed?subject=unsubscribe%20cat-users
> Or use the following link:
> https://lists.geant.org/sympa/sigrequest/cat-users
--
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
2, avenue de l'Université
L-4365 Esch-sur-Alzette
Tel: +352 424409 1
Fax: +352 422473
PGP key updated to 4096 Bit RSA - I will encrypt all mails if the
recipient's key is known to me
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xC0DE6A358A39DC66
Attachment:
0xC0DE6A358A39DC66.asc
Description: application/pgp-keys
Attachment:
signature.asc
Description: OpenPGP digital signature
-
RE: [[cat-users]] Unhandled exception after idp authentication,
Fenwick, David, 01/11/2019
- <Possible follow-up(s)>
-
RE: [[cat-users]] Unhandled exception after idp authentication,
Fenwick, David, 01/23/2019
- Re: [[cat-users]] Unhandled exception after idp authentication, Stefan Winter, 01/28/2019
Archive powered by MHonArc 2.6.19+.
