Skip to Content.
Sympa Menu

cat-users - [[cat-users]] Trouble logging into cat.eduroam.org — suspicious pairwise-id format

cat-users AT lists.geant.org

Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)

List archive

[[cat-users]] Trouble logging into cat.eduroam.org — suspicious pairwise-id format


Chronological Thread  
  • From: "Stobbe, Erik" <address@concealed>
  • To: "address@concealed" <address@concealed>
  • Cc: Thoß, Thomas <address@concealed>
  • Subject: [[cat-users]] Trouble logging into cat.eduroam.org — suspicious pairwise-id format
  • Date: Wed, 10 Dec 2025 09:30:34 +0000
  • Accept-language: de-DE, en-US
  • Ironport-data: A9a23:OOp+56CCkPoNlRVW/3ziw5YqxClBgxIJ4kV8jS/XYbTApDpw1GQAx mRODGyEb/eMajb0fd5xaomw90gF7ZGGn9dnTANkpHpgZkwRpJueD7x1DG+rZn/PcZeTJK5Ex 5xGNomdc55sJpP4jk3wWlQ0hSAkjclkfpKlVqicfHs3HVM4IMsYoUoLs/YjhYJ1isSODQqIu Nfjy+XSI1bNNwRcawr40Ird7kk31BjOkGlA5AFnP6kT5Aa2e0Q9VfrzG4ngchMUfaEMdgKKb 76r5K20+Grf4yAsBruN+p7nclcHS6LlJgOHjHxbQcCK2nCucQRrj87XnNJFAatmo23hc+JZk b2hhrTpIesdBZAgrcxGO/Vu/4OSCoUdkFPPCSDXXcV+VCQqeVO0qxllJBle0YH1Zo+bDEkWn cH0JgzhYTiI3sGWzpOaENM8j8scfZXLNao5uFtJmGSx4fYOGfgvQo3Y6cEd0Sc7hoUUW8TyW Yw/ZCYHgBboOkUJawtRUs5g2rny7pX8W2QwRFa9iLA24C7o0At72rXFMMXaP9iXA8lY9qqdj jmWojimXkxBXDCZ4RDY3m2g37fhpB7YQN4XMLyX3cFT0ULGkwT/DzVTDzNXu8KRgUeiHs9EJ lYP0i4vtrQpskOmR9/hGRqirxa5UgU0SdZOVuAq4wHIkOzG7xjfAGUYJtJcVOEbWAYNbWRC/ je0cxnBX1SDbJX9paqhy4qp
  • Ironport-hdrordr: A9a23:VJGYCKwVvX/webXkgIYaKrPwHr1zdoMgy1knxilNoERuA6mlf8 DHppsmPGzP+VIssRAb6Ki90ca7MBDhHPJOjLX5Xo3SJzUO2lHYTr2KhLGKq1aLJ8SUzIBgPN JbE5SWf+eQMbEVt6rHCUKDYrEdKZG8gcaVbMnlvg5QcT0=

Hello everyone,

I am administrator for the IdP of Hochschule für Wirtschaft und Gesellschaft Ludwigshafen (HWG LU) . I’m writing here because I encounter a strange issue when trying to log in to cat.eduroam.org — maybe someone has seen it before or can give advice.

What works:

 

  • Login at other SPs (e.g. emp.eduroam.de) works flawlessly — our IdP uses a valid SAML pairwise-id plus correct eduroam entitlement; authentication and attribute release succeed.
  • Our IdP configuration has been reviewed multiple times: we generate a scoped pairwise-id (with domain-based scope), using a standard SAML2ScopedString.

 

What fails / what looks strange at cat.eduroam.org:

 

  • On cat.eduroam.org the displayed pairwise-id looks unusual: it contains a suffix with !https://…, i.e. after the scope or IdP-EntityID a URL appears.

  • After login, the expected attributes (e.g. eduPersonEntitlement, displayName, mail, …) are not shown, and our organization is not recognized / not listed.

 

What we’ve checked:

  • Our pairwise-id generation is spec-compliant: scoped attribute, domain as scope, no extraneous attributes, no persistentID/legacy-ID released.
  • Login to other non-CAT SPs works — so IdP seems to operate correctly and releases correct identifiers and attributes.
  • Despite that, the login to cat.eduroam.org uses a different-looking pairwise-id (with URL suffix), though we have disabled all URL-based persistentID or metadata-related identifiers in our configuration.

Here the attribute-filter.xml from our IDP:

Here the eduPersonEntitlement-attribute:

Thank you very much for any pointers.

Best regards,

 

 

Erik Stobbe

Hochschule für Wirtschaft und Gesellschaft Ludwigshafen

IT-Service / Service Owner Linux / Raum C 1.230
t +49 621 5203 - 183   m +49 1590 1815791

e address@concealed

w www.hwg-lu.de

a Ernst-Boehe-Straße 4-6, 67059 Ludwigshafen

 




Archive powered by MHonArc 2.6.19+.

Top of Page