By: Anthony Supinski user 29 Apr 2016 at 11:14 a.m. CDT

4 Responses
Anthony Supinski gravatar
I've been setting up asimba using the OxTrust Gui and I've gotten to the point where my SP-> asimba IDP leg seems to be working but there is an error before the initiation of the asimba SP -> Idp leg. I was going to dig around in the asimba.xml configuration and see if I could find anything but I can't find one of the xml files that have the metadata set up for my SP and Idp... so: 1. When configuring asimba via OxTrust where does the configuration go? 2. Any ideas on this error(logs below) note the amazon idp is the idp configured to be used for this sp no not sure what "no suitable bindings found" means: INFO | jvm 1 | 2016/04/29 16:12:23 | <saml:Issuer>Catalog</saml:Issuer> INFO | jvm 1 | 2016/04/29 16:12:23 | <samlp:NameIDPolicy AllowCreate="true" Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"/> INFO | jvm 1 | 2016/04/29 16:12:23 | <samlp:RequestedAuthnContext Comparison="exact"> INFO | jvm 1 | 2016/04/29 16:12:23 | <saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:X509</saml:AuthnContextClassRef> INFO | jvm 1 | 2016/04/29 16:12:23 | </samlp:RequestedAuthnContext> INFO | jvm 1 | 2016/04/29 16:12:23 | </samlp:AuthnRequest> INFO | jvm 1 | 2016/04/29 16:12:23 | INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] WebBrowserSSO Put on map? urlpath.context=web INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] AuthenticationRequestProtocol AssertionConsumerServiceURL: INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] AuthenticationRequestProtocol ProtocolBinding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] AuthenticationRequestProtocol NameIDPolicy AllowCreate in request: : true INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] AuthenticationRequestProtocol Using NameID Format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] AuthenticationRequestProtocol Using requested RequestedAuthnContext ClassRefs: [urn:oasis:names:tc:SAML:2.0:ac:classes:X509] INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] AuthenticationRequestProtocol ForcedAuthentication: false INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] AuthenticationRequestProtocol ProviderName: OpenSesame INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] WebBrowserSSO Using proxied requested AuthnContextClassRefs: [urn:oasis:names:tc:SAML:2.0:ac:classes:X509] INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] WebBrowserSSO Using proxied requested AuthnContextComparisonType: exact INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [INFO] MemorySessionFactory New session(s) added: NRGX3LE0PopDeSxE0jWY5Q for requestor 'Catalog' INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [INFO] EventLogger SESSION_CREATED, NRGX3LE0PopDeSxE0jWY5Q, null, null, null,, 2, AUTHN_INITIATION_SUCCESSFUL, Catalog, SAML2 Profile, null INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [INFO] EventLogger PRE_AUTHZ_OK, NRGX3LE0PopDeSxE0jWY5Q, null, null, null,, 1, USER_PRE_AUTHORIZED, Catalog, WebSSO, null INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [DEBUG] SSOService No valid TGT Cookie found INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:22] [INFO] EventLogger AUTHN_SELECTION_IN_PROGRESS, NRGX3LE0PopDeSxE0jWY5Q, null, null, null,, 1, TGT_NOT_SUFFICIENT, Catalog, WebSSO, null INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [DEBUG] WebProfile No (optional) requestor specific 'web.always_show_select_form' property found for requestor with ID: Catalog INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [DEBUG] WebProfile No (optional) requestorpool specific 'web.always_show_select_form' property found for requestorpool with ID: requestorpool.1 INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [INFO] EventLogger AUTHN_SELECTION_OK, NRGX3LE0PopDeSxE0jWY5Q, null, null, null,, 1, AUTHN_PROFILE_SELECTED, Catalog, WebSSO, null INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [INFO] SAML2AuthenticationMethod No 'i' value found in URLPath Context path ('web') INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [DEBUG] WebBrowserSSOProfile Request recieved: INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [DEBUG] SAML2IDP Returning existing MetadataProvider for SAML2 IDP 'urn:amazon:webservices' INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [DEBUG] AbstractAuthNMethodSAML2Profile Could not retrieve metadata (IDP Role) for IdP with ID: urn:amazon:webservices INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [DEBUG] WebBrowserSSOProfile Could not determine binding, no IDP role descriptor found INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [ERROR] WebBrowserSSOProfile Authentication request could not be formed, since no suitable binding can be found INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [INFO] EventLogger AUTHN_IN_PROGRESS, NRGX3LE0PopDeSxE0jWY5Q, null, null, null,, 1, AUTHN_METHOD_FAILED, Catalog, SAML2AuthenticationMethod_RemoteSAML, 0001 INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [ERROR] WebProfile Internal error during authN profile selection INFO | jvm 1 | 2016/04/29 16:12:23 | com.alfaariss.oa.OAException: 0001 INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.authentication.remote.saml2.profile.sso.WebBrowserSSOProfile.createAuthNRequest( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.authentication.remote.saml2.profile.sso.WebBrowserSSOProfile.process( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.authentication.remote.saml2.SAML2AuthenticationMethod.authenticate( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.authentication.web.AuthenticationManager.authenticate( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.profile.web.WebProfile.handleAuthentication( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.profile.web.WebProfile.handleAuthenticationSelection( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.profile.web.WebProfile.checkTGT( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.profile.web.WebProfile.handlePreAuthorization( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.profile.web.WebProfile.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.WebSSOServlet.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at javax.servlet.http.HttpServlet.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.tomcat.websocket.server.WsFilter.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationDispatcher.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationDispatcher.processRequest( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationDispatcher.doForward( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationDispatcher.forward( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.util.saml2.profile.AbstractSAML2Profile.forwardUser( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.profile.saml2.profile.sso.WebBrowserSSO.processAuthenticationRequest( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.profile.saml2.profile.sso.WebBrowserSSO.processSAMLRequest( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.profile.saml2.profile.sso.WebBrowserSSO.process( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.profile.saml2.SAML2Profile.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.OAServlet.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at javax.servlet.http.HttpServlet.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.tomcat.websocket.server.WsFilter.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.StandardWrapperValve.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.StandardContextValve.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.authenticator.AuthenticatorBase.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.StandardHostValve.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.valves.ErrorReportValve.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.StandardEngineValve.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.connector.CoyoteAdapter.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.coyote.ajp.AjpProcessor.process( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process( INFO | jvm 1 | 2016/04/29 16:12:23 | at$ INFO | jvm 1 | 2016/04/29 16:12:23 | at java.util.concurrent.ThreadPoolExecutor.runWorker( INFO | jvm 1 | 2016/04/29 16:12:23 | at java.util.concurrent.ThreadPoolExecutor$ INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.tomcat.util.threads.TaskThread$ INFO | jvm 1 | 2016/04/29 16:12:23 | at INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [INFO] EventLogger AUTHN_IN_PROGRESS, NRGX3LE0PopDeSxE0jWY5Q, null, null, null,, 1, INTERNAL_ERROR, Catalog, WebSSO, null INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [ERROR] WebProfile Internal error while processing request code=(1), session=(NRGX3LE0PopDeSxE0jWY5Q) INFO | jvm 1 | 2016/04/29 16:12:23 | com.alfaariss.oa.sso.SSOException: 0001 INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.profile.web.WebProfile.handleAuthenticationSelection( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.profile.web.WebProfile.checkTGT( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.profile.web.WebProfile.handlePreAuthorization( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.profile.web.WebProfile.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.sso.web.WebSSOServlet.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at javax.servlet.http.HttpServlet.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.tomcat.websocket.server.WsFilter.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationDispatcher.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationDispatcher.processRequest( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationDispatcher.doForward( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationDispatcher.forward( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.util.saml2.profile.AbstractSAML2Profile.forwardUser( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.profile.saml2.profile.sso.WebBrowserSSO.processAuthenticationRequest( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.profile.saml2.profile.sso.WebBrowserSSO.processSAMLRequest( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.profile.saml2.profile.sso.WebBrowserSSO.process( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.profile.saml2.SAML2Profile.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at com.alfaariss.oa.OAServlet.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at javax.servlet.http.HttpServlet.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.tomcat.websocket.server.WsFilter.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.ApplicationFilterChain.doFilter( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.StandardWrapperValve.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.StandardContextValve.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.authenticator.AuthenticatorBase.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.StandardHostValve.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.valves.ErrorReportValve.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.core.StandardEngineValve.invoke( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.catalina.connector.CoyoteAdapter.service( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.coyote.ajp.AjpProcessor.process( INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process( INFO | jvm 1 | 2016/04/29 16:12:23 | at$ INFO | jvm 1 | 2016/04/29 16:12:23 | at java.util.concurrent.ThreadPoolExecutor.runWorker( INFO | jvm 1 | 2016/04/29 16:12:23 | at java.util.concurrent.ThreadPoolExecutor$ INFO | jvm 1 | 2016/04/29 16:12:23 | at org.apache.tomcat.util.threads.TaskThread$ INFO | jvm 1 | 2016/04/29 16:12:23 | at INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [INFO] MemorySessionFactory Session Expired: NRGX3LE0PopDeSxE0jWY5Q INFO | jvm 1 | 2016/04/29 16:12:23 | (ASIMBAWA) [2016-04-29 16:12:23] [INFO] EventLogger AUTHN_IN_PROGRESS, NRGX3LE0PopDeSxE0jWY5Q, null, null, null, null, 1, SESSION_EXPIRED, Catalog, SessionFactory, null Thanks!

By Mohib Zico staff 30 Apr 2016 at 2:26 p.m. CDT

Mohib Zico gravatar
Hi Anthony, >> I was going to dig around in the asimba.xml configuration and see if I could find anything but I can't find one of the xml files that have the metadata set up for my SP and Idp... Asimba configuration is inside LDAP, not in that XML file. Regarding stack trace: can you please share the log with pastebin or some services like that? It's really hard to read logs here.

By Anthony Supinski user 02 May 2016 at 12:22 p.m. CDT

Anthony Supinski gravatar
:) here is the log any recomendations on LDAP viewing or querying? Thanks!

By Mohib Zico staff 02 May 2016 at 1:22 p.m. CDT

Mohib Zico gravatar
Thanks. >> This is the problem. Because of a network issue... your Asimba server is unable to load metadata of this address.

By Anthony Supinski user 02 May 2016 at 2:05 p.m. CDT

Anthony Supinski gravatar
I assume you meant to paste some other url than the current support url, I'm betting the AWS url so I'll start looking at that, thanks!