|
RE: Shibboleth idp and CAS: msg#00083java.jasig.cas.user
This is a multi-part message in MIME format. I reverted to a test using testshib so I could see the logs
on the sp side of the house.
The sp does try to access the -idp/AA but has SSL problems
- the error log from the sp side:
2006-12-12 11:58:19 INFO
shibtarget.SessionCache [1110] sessionGet: trying to get new attributes for
session (ID=_a2f06aa1d3dedbfd05977d07da54ebc8)
2006-12-12 11:58:19 DEBUG
shibtarget.SessionCache [1110] sessionGet: trying to query an AA...
2006-12-12 11:58:19 DEBUG
SAML.SAMLSOAPHTTPBinding.CURLPool [1110] sessionGet: getting connection handle
to https://web2.ametsoc.org:8443/shibboleth-idp/AA
2006-12-12 11:58:19 DEBUG
SAML.SAMLSOAPHTTPBinding.CURLPool [1110] sessionGet: nothing free in pool,
returning new connection handle
2006-12-12 11:58:19 INFO
SAML.SAMLSOAPHTTPBinding [1110] sessionGet: sending SOAP message to
https://web2.ametsoc.org:8443/shibboleth-idp/AA
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet: About to connect() to web2.ametsoc.org port
8443
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet: Trying 64.55.87.5...
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet: connected
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet: Connected to web2.ametsoc.org (64.55.87.5) port
8443
2006-12-12 11:58:19 DEBUG
shibtarget.ShibHTTPHook [1110] sessionGet: OpenSAML invoked SSL context
callback
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet: SSLv3, TLS handshake, Client hello
(1):
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet: SSLv3, TLS handshake, Server hello
(2):
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet: SSLv3, TLS handshake, CERT (11):
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet:
2006-12-12 11:58:19 DEBUG OpenSSL
[1110] sessionGet: invoking default X509 verify callback
2006-12-12 11:58:19 DEBUG
Shibboleth.Trust.Basic [1110] sessionGet: comparing certificate to
KeyDescriptors
2006-12-12 11:58:19 DEBUG
Shibboleth.Trust.Basic [1110] sessionGet: KeyDescriptor resolved into a
certificate, comparing it...
2006-12-12 11:58:19 DEBUG
Shibboleth.Trust.Basic [1110] sessionGet: certificate did not match
2006-12-12 11:58:19 DEBUG
Shibboleth.Trust.Basic [1110] sessionGet: failed to find an exact match for
certificate in KeyDescriptors
2006-12-12 11:58:19 DEBUG
Shibboleth.Trust.Shibboleth [1110] sessionGet: performing certificate path
validation...
2006-12-12 11:58:19 DEBUG
Shibboleth.Trust.Shibboleth [1110] sessionGet: failed to validate certificate
chain using KeyAuthority extensions
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet: SSLv3, TLS alert, Server hello (2):
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet: SSL certificate problem, verify that the CA cert
is OK. Details:
error:14090086:SSL
routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
2006-12-12 11:58:19 DEBUG
SAML.libcurl [1110] sessionGet: Closing connection #0
2006-12-12 11:58:19 ERROR
SAML.SAMLSOAPHTTPBinding [1110] sessionGet: failed while contacting SAML
responder: SSL certificate problem, verify that the CA cert is OK.
Details:
error:14090086:SSL
routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify failed
2006-12-12 11:58:19 ERROR
shibtarget.SessionCache [1110] sessionGet: caught SAML exception during SAML
attribute query: SOAPHTTPBindingProvider::send() failed while contacting SAML
responder: SSL certificate problem, verify that the CA cert is OK.
Details:
Not sure why this is failing when I am working ok with a cassified servlets-examples in tomcat. Can
anyone shed some light?
Thanks, Pat
From: Patrick MacDonald
[mailto:patmac00-Wuw85uim5zDR7s880joybQ@xxxxxxxxxxxxxxxx]
Sent: Tuesday, December 12, 2006 11:44 AM To: cas-c5E7yoNEsvRIM2btvs0Z1A@xxxxxxxxxxxxxxxx; shibboleth-users-H4aWS73dXup+qImEYqgU8Q@xxxxxxxxxxxxxxxx Subject: Shibboleth idp and CAS
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | websso-3.0.5 and webflow problem, upasana immidi |
|---|---|
| Next by Date: | Problem with LDAP filter values substitution, André Cruz |
| Previous by Thread: | Shibboleth idp and CAS, Patrick MacDonald |
| Next by Thread: | RE: Shibboleth idp and CAS, Patrick MacDonald |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |