Hi
I configured the relaying party, but now I have a different issue. It seems like the SAML POST now goes through, but I do not get a login prompt on the GLUU side. Using the SAML Tracer I get the following:
**SAML POST**
```
POST https://idp.artest.sanlam.co.za/idp/profile/SAML2/POST/SSO HTTP/1.1
Host: idp.artest.sanlam.co.za
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: https://ig.artest.sanlam.co.za:8443/osp/a/idm/auth/oauth2/grant?response_type=token&redirect_uri=https://ig.artest.sanlam.co.za:8443/oauth.html&client_id=iac&state=gromitstate0.0006725695683482691
Cookie: JSESSIONID=1t22o97nvf2kmmnohnojiwja3; session_state=f3867448-3c47-4621-86c7-2e1537128720
Content-Type: application/x-www-form-urlencoded
Content-Length: 1162
HTTP/?.? 302 Found
Date: Thu, 02 Mar 2017 11:19:10 GMT
Server: Jetty(9.3.15.v20161220)
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
x-content-type-options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-store
Location: https://idp.artest.sanlam.co.za/idp/profile/SAML2/POST/SSO?execution=e1s1
Content-Length: 0
Set-Cookie: JSESSIONID=kh9cq43dp7m61nffw6pm2gn98;Path=/idp;Secure;HttpOnly
Connection: close
```
Then I get the following:
```
GET https://idp.artest.sanlam.co.za/idp/profile/SAML2/POST/SSO?execution=e1s1 HTTP/1.1
Host: idp.artest.sanlam.co.za
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: https://ig.artest.sanlam.co.za:8443/osp/a/idm/auth/oauth2/grant?response_type=token&redirect_uri=https://ig.artest.sanlam.co.za:8443/oauth.html&client_id=iac&state=gromitstate0.0006725695683482691
Cookie: JSESSIONID=kh9cq43dp7m61nffw6pm2gn98; session_state=f3867448-3c47-4621-86c7-2e1537128720
HTTP/?.? 302 Found
Date: Thu, 02 Mar 2017 11:19:10 GMT
Server: Jetty(9.3.15.v20161220)
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
x-content-type-options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Cache-Control: no-store
Location: https://idp.artest.sanlam.co.za/idp/Authn/RemoteUser?conversation=e1s1
Content-Length: 0
Connection: close
```
Followed by
```
GET https://idp.artest.sanlam.co.za/idp/Authn/RemoteUser?conversation=e1s1 HTTP/1.1
Host: idp.artest.sanlam.co.za
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: https://ig.artest.sanlam.co.za:8443/osp/a/idm/auth/oauth2/grant?response_type=token&redirect_uri=https://ig.artest.sanlam.co.za:8443/oauth.html&client_id=iac&state=gromitstate0.0006725695683482691
Cookie: JSESSIONID=kh9cq43dp7m61nffw6pm2gn98; session_state=f3867448-3c47-4621-86c7-2e1537128720
HTTP/?.? 302 Found
Date: Thu, 02 Mar 2017 11:19:10 GMT
Server: Jetty(9.3.15.v20161220)
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
x-content-type-options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Location: https://idp.artest.sanlam.co.za/oxauth/seam/resource/restv1/oxauth/authorize?scope=openid+profile+email+user_name&response_type=code+id_token&redirect_uri=https%3A%2F%2Fidp.artest.sanlam.co.za%2Fidp%2Fauth-code.jsp&nonce=nonce&client_id=%40%21CB94.D7B0.DB10.875F%210001%215341.9D26%210008%216031.3667
Content-Length: 0
Connection: close
```
Followed by
```
GET https://idp.artest.sanlam.co.za/oxauth/seam/resource/restv1/oxauth/authorize?scope=openid+profile+email+user_name&response_type=code+id_token&redirect_uri=https%3A%2F%2Fidp.artest.sanlam.co.za%2Fidp%2Fauth-code.jsp&nonce=nonce&client_id=%40%21CB94.D7B0.DB10.875F%210001%215341.9D26%210008%216031.3667 HTTP/1.1
Host: idp.artest.sanlam.co.za
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: https://ig.artest.sanlam.co.za:8443/osp/a/idm/auth/oauth2/grant?response_type=token&redirect_uri=https://ig.artest.sanlam.co.za:8443/oauth.html&client_id=iac&state=gromitstate0.0006725695683482691
Cookie: JSESSIONID=16o50uyk530488efta8n3aaf5; javax.faces.ClientToken=zapDTxBpKPzdFaqhupfczAGH4BgMDHSXxbhImhrrYDiCyNx1rH; session_state=f3867448-3c47-4621-86c7-2e1537128720
HTTP/?.? 302 Found
Date: Thu, 02 Mar 2017 11:19:10 GMT
Server: Jetty(9.3.15.v20161220)
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
x-content-type-options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Location: https://idp.artest.sanlam.co.za/idp/auth-code.jsp#code=c5d03fae-c3dc-4bd8-86d9-14a616348bb4&scope=openid+user_name+profile+email&id_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJodHRwczovL2lkcC5hcnRlc3Quc2FubGFtLmNvLnphIiwiYXVkIjoiQCFDQjk0LkQ3QjAuREIxMC44NzVGITAwMDEhNTM0MS45RDI2ITAwMDghNjAzMS4zNjY3IiwiZXhwIjoxNDg4NDU3MTUwLCJpYXQiOjE0ODg0NTM1NTAsIm5vbmNlIjoibm9uY2UiLCJhdXRoX3RpbWUiOjE0ODg0NTIwODIsImNfaGFzaCI6Imo0UjJkZVIzVDZqb0Yzc3FzN0FIbGciLCJveFZhbGlkYXRpb25VUkkiOiJodHRwczovL2lkcC5hcnRlc3Quc2FubGFtLmNvLnphL294YXV0aC9vcGlmcmFtZSIsIm94T3BlbklEQ29ubmVjdFZlcnNpb24iOiJvcGVuaWRjb25uZWN0LTEuMCIsInN1YiI6IkAhQ0I5NC5EN0IwLkRCMTAuODc1RiEwMDAxITUzNDEuOUQyNiEwMDAwIUIyRDguNEE5NCJ9.JUQxLMnRVpH18sNrwpEEAJsmI7yCQnB_KpBiSkFqnvE&state&session_state=f3867448-3c47-4621-86c7-2e1537128720
Content-Length: 0
access-control-allow-origin: *
Connection: close
```
and finally
```
GET https://idp.artest.sanlam.co.za/idp/auth-code.jsp#code=c5d03fae-c3dc-4bd8-86d9-14a616348bb4&scope=openid+user_name+profile+email&id_token=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJodHRwczovL2lkcC5hcnRlc3Quc2FubGFtLmNvLnphIiwiYXVkIjoiQCFDQjk0LkQ3QjAuREIxMC44NzVGITAwMDEhNTM0MS45RDI2ITAwMDghNjAzMS4zNjY3IiwiZXhwIjoxNDg4NDU3MTUwLCJpYXQiOjE0ODg0NTM1NTAsIm5vbmNlIjoibm9uY2UiLCJhdXRoX3RpbWUiOjE0ODg0NTIwODIsImNfaGFzaCI6Imo0UjJkZVIzVDZqb0Yzc3FzN0FIbGciLCJveFZhbGlkYXRpb25VUkkiOiJodHRwczovL2lkcC5hcnRlc3Quc2FubGFtLmNvLnphL294YXV0aC9vcGlmcmFtZSIsIm94T3BlbklEQ29ubmVjdFZlcnNpb24iOiJvcGVuaWRjb25uZWN0LTEuMCIsInN1YiI6IkAhQ0I5NC5EN0IwLkRCMTAuODc1RiEwMDAxITUzNDEuOUQyNiEwMDAwIUIyRDguNEE5NCJ9.JUQxLMnRVpH18sNrwpEEAJsmI7yCQnB_KpBiSkFqnvE&state&session_state=f3867448-3c47-4621-86c7-2e1537128720 HTTP/1.1
Host: idp.artest.sanlam.co.za
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: https://ig.artest.sanlam.co.za:8443/osp/a/idm/auth/oauth2/grant?response_type=token&redirect_uri=https://ig.artest.sanlam.co.za:8443/oauth.html&client_id=iac&state=gromitstate0.0006725695683482691
Cookie: JSESSIONID=kh9cq43dp7m61nffw6pm2gn98; session_state=f3867448-3c47-4621-86c7-2e1537128720
HTTP/?.? 200 OK
Date: Thu, 02 Mar 2017 11:19:10 GMT
Server: Jetty(9.3.15.v20161220)
X-Frame-Options: SAMEORIGIN
X-XSS-Protection: 1; mode=block
x-content-type-options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Content-Type: text/html;charset=utf-8
Content-Length: 1496
Connection: close
```
If I log into the GLUU server at https://idp.artest.sanlam.co.za/oxauth/login and then hit the NetIQ AR url it works and I am logged into NetIQ AR. So it seems like GLUU is not showing me the login screen or something is misconfigured. I have tried both Firefox and Chrome.