Skip to Content.

cat-users - [[cat-users]] Unable to authenticate

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive


[[cat-users]] Unable to authenticate


Chronological Thread 
  • From: Matthew Slowe <Matthew.Slowe AT jisc.ac.uk>
  • To: "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
  • Subject: [[cat-users]] Unable to authenticate
  • Date: Tue, 28 Jul 2020 09:18:08 +0000
  • Accept-language: en-GB, en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=jisc.ac.uk; dmarc=pass action=none header.from=jisc.ac.uk; dkim=pass header.d=jisc.ac.uk; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ebqUrAsqsmdNJEcZCGBHyoWd3xpsa+0vJ1G4JYV3Y18=; b=CjHDBxA/KGiaCw652IO3ENR2Ro+QEhyMiD0mF0pQaAuEAebJBEtn8WxkR2H/Vs3cX41Td1xYHeHqC4pKgsEiA5PM41fueVTyoEXcZPmaPah/4u4H9d8nUN6eONXnp1dmYQMoDxpggQKywyWY6GUvoATLFIqRM6PFiwArKV5f5F7eOLifJJfN+sWqhfRYxtljSrfdfa40TikMX2BFdRPF+uSaYjpkcrRmmgevnucHNCXJIg7Cc8r9M13cFPB4K7Ls1Lt5okXoJfaC+O3NILsSUFTlyikDCM+x5OyXGq82E8YTZ67ij4cWddTOU1308cm7kY1enB3pLGSUObLyNfc8ww==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=EOVmQm2V2DFdcG9a6RVzRLUPEIUMB6B2H7l5PAOcHszSpMtOu/lYci4i/yGJiDeJa3BVgQGz1DSUIEiGGxAUdU3dxpdvbxL6EfhUm7CKIpPyNlPEoit/T1I1xgnwsmY6EHPFNfC9+JNRAcjEHcKvZBFB1qoC1wuSBkBOX1JVLd+DKeKzbDDR89LFMGYxCjfv5rFp3iqFfmUkHgs4toDNsc4+QJvum4SK9MWLHYycVG+9QnpplKaNHB3JabxSd7iQO0RjMN3/v+Bdl57sRaqvK4pOeIH+rdg1p2FB7dlyGx/AQR3bCOylxkZzAIfFR41N8LG8qnsLpjnau3aEBtENwA==
  • Authentication-results: lists.geant.org; dkim=none (message not signed) header.d=none;lists.geant.org; dmarc=none action=none header.from=jisc.ac.uk;

Morning,

On behalf of a new CAT member organisation, they're having trouble
authenticating to the CAT Admin portal. SimpleSAMLphp is returning an error
"Failed to decrypt XML element". We've checked the logs on the IdP (look ok)
and can access the UK Federation's Test SP ok, too.

SimpleSAML_Error_Error: UNHANDLEDEXCEPTION
Backtrace:
1 www/_include.php:45 (SimpleSAML_exception_handler)
0 [builtin] (N/A)
Caused by: Exception: Failed to decrypt XML element.
Backtrace:
6 vendor/simplesamlphp/saml2/src/SAML2/Utils.php:568
(SAML2\Utils::decryptElement)
5 vendor/simplesamlphp/saml2/src/SAML2/EncryptedAssertion.php:93
(SAML2\EncryptedAssertion::getAssertion)
4 modules/saml/lib/Message.php:398 (sspmod_saml_Message::decryptAssertion)
3 modules/saml/lib/Message.php:611 (sspmod_saml_Message::processAssertion)
2 modules/saml/lib/Message.php:578 (sspmod_saml_Message::processResponse)
1 modules/saml/www/sp/saml2-acs.php:129 (require)
0 www/module.php:135 (N/A)

The tracking code was 5d4e392eee at about 08:53Z today.

Is this something at the SimpleSAMLphp end or something wrong with the
assertion being generated by their IdP?

Thanks,
--
Matthew Slowe
Technical Specialist - Trust & Identity, Jisc
Lumen House, Library Avenue, Harwell Oxford, Didcot, OX11 0SG


Attachment: smime.p7s
Description: S/MIME cryptographic signature




Archive powered by MHonArc 2.6.19.

Top of Page