Symantec Access Management

Expand all | Collapse all

SLO for SAML SP

Jump to Best Answer
  • 1.  SLO for SAML SP

    Posted 12-10-2019 11:12 PM
    HI Team,

    When I have enabled SLO and found below issue.

    SLO fails with SOAP processing Error. Exception processing request.

    Please assist what is the problem here ?

    https://ogqganefubgfipj-xxxxxxx.accounts.apigee.io/saml/SingleLogout/alias/xxxxxx-xj3atxs4pncp1hlw.apigee-saml-login?SAMLResponse=jZLNasMwEIRfxehuy%2FJfHGEbSnMJpJc65NBLkWXZVlAk1SvRPH4dh1B6CT0t7M58yw5bHcxovHsXYI0GEewEOKmZk0bXaHLOAsXYjF8j02Lw3ThIew6v55S5K2RWc0sm9R0xzo3XDiJm5ShEJA0GdlG4lXpU4r4CMyUZ%2FIO1IsKbP1RmlBoF%2B12NPrNkk3VxnPN8k%2BZ9ORQdGQQpslJsiy4e0i7N%2BkWqH6ccTY1YUk75IMs%2BLoY849m0zfJCkqlMimIqFzWAF3sNjmlXoyQm25AkISHHOKVxSZP8AwUnMcOaRhLFKLhelIYa%2BVlTw0AC1ewigDpO25e3A1001M7GGW4UaioNhK475ruRLo3nZgYg5lv6qDHWeQi5Mr4PZW8r%2FEtrqtaxZfqor6YXwYkpL57TYVXT1nMuABBuKvwA4b%2BP0PwA&RelayState={"redirect":"https://dns/logout","client_id":"portal-bnj0eaxbar"}

    logout response from siteminder.

    <LogoutResponse xmlns="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://xxxxxxx-xj3atxs4pncp1hlw.accounts.apigee.io/saml/SingleLogout/alias/xxxxxxxx-xj3atxs4pncp1hlw.apigee-saml-login" ID="_4274b005c5735d8f6b1fe1648e96b0f3b34d" InResponseTo="a28h5fi8d06f54c4h9456i1h8266h8" IssueInstant="2019-12-11T03:08:25Z" Version="2.0">
    <ns1:Issuer xmlns:ns1="urn:oasis:names:tc:SAML:2.0:assertion">optus-cloud-idp</ns1:Issuer>
    <Status>
    <StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
    </Status>
    <script/>
    </LogoutResponse>


    Here I have provided complete logs.

    [12/11/2019][03:01:26][4866][140180963440384][][FWSBase.java][getSLOGUIDCookie][Entering [configurationContextData: com.netegrity.siteminder.agentcommon.framework.d@62e2bc27]]

    [12/11/2019][03:01:26][4866][140180963440384][][FWSBase.java][getSLOGUIDCookie][Leaving [guid: 243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c]]

    [12/11/2019][03:01:26][4866][140180963440384][][agentcommon][][Requesting data for ConfigManager ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/SmHost.conf and SmAgentConfig ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/WebAgent.conf]

    [12/11/2019][03:01:26][4866][140180963440384][][agentcommon][][Administration Manager is returning data for ConfigManager ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/SmHost.conf and SmAgentConfig ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/WebAgent.conf]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][doPost][Receiving request at SAML2 SLO Logout URL through POST method [CHECKPOINT = SLOSAML2_LOGOUTSERVICEPOST_RECEIVE]]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][doPost][SAML2 Single Logout Service received POST request.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][doRequestLog][Requesting Host: 10.121.89.131 Requesting Host IP: 10.121.89.131 Request protocol: HTTP/1.1 Request was secure: true Authentication type: null]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][canDoSOAP][Request is NOT SOAP:  /affwebservices/public/saml2slo]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][doPostImpl][ENTER:doPostImpl]

    [12/11/2019][03:01:26][4866][140180963440384][][SLOService.java][validateRequest][Validate GET request for necessary parameters [CHECKPOINT = SLOSAML2_GETREQUEST_VALIDATE]]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][doPostImpl][SAML message received=<?xml version="1.0" encoding="UTF-8"?><saml2p:LogoutRequest xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://sitemindersps/affwebservices/public/saml2slo" ID="a28h5fi8d06f54c4h9456i1h8266h8" IssueInstant="2019-12-11T03:07:59.623Z" Version="2.0"><saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login</saml2:Issuer><ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/><ds:Reference URI="#a28h5fi8d06f54c4h9456i1h8266h8"><ds:Transforms><ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms><ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/><ds:DigestValue>Ve10BMXbtZ6F0y/yv/+IW5voNWs5IzaEcriLK1F8sZE=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>pCEOKn81VQ7WcJ06LlXyS7c0Ye7tpdd/8lvIHi0msjGpTWw+gXpsrs/QCaYd2ZVTSuc/HKuAFml/m8ZX3r+VsxOzdJ2fy1A8F/u3DGRGDsoiuQUya5Z3s6dRURhXRAvdHFXnVz5bGhmeB/2qujSaPcZc2LivGwNpDzOmlTFspSPoGH80UrCr/dSvzoY1HaNPtkSqcbW5o6bkX3dEP5QQt5wpWG6HCKHZwLnuWCw7NeRg1RhbKmHvH09PnfNF4fOGwOWCz/S3TcxhmJuxby0RVWzPkoF9K2lYF45J+CQB8SwKP3IyJq3P+GvuBL7y3UUnZbbCtS1LaefY3IbfXUI8mA==</ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate>MIIFozCCBIugAwIBAgIRAKG9zQebVRRBAQAAAAAaw0swDQYJKoZIhvcNAQELBQAwQjELMAkGA1UE

    BhMCVVMxHjAcBgNVBAoTFUdvb2dsZSBUcnVzdCBTZXJ2aWNlczETMBEGA1UEAxMKR1RTIENBIDFP

    MTAeFw0xOTAxMTQxNzQ2NTVaFw0yMDAxMTMxNzQ2NTVaMGoxCzAJBgNVBAYTAlVTMRMwEQYDVQQI

    EwpDYWxpZm9ybmlhMRYwFAYDVQQHEw1Nb3VudGFpbiBWaWV3MRMwEQYDVQQKEwpHb29nbGUgTExD

    MRkwFwYDVQQDExBsb2dpbi5hcGlnZWUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC

    AQEAynAEiaNMvscrrw5/dbQdIHsjX6gNCRNe7HWDWspX5su46hk6KGaEX8sYWmHLR5SqTyQpVZ/4

    8GDyk2P5NJNOCzNyJDL+on/ZQ2GA5Pu0Jsq0XcOIGbHWJ7JX2elT3DQ7Cf3zhreLzaUKcnFEat8z

    3dufY/qOblRj9tZ7Q8DwPE3W9ElQOlKDOMl9q+iIxge/W85Bu1nWTjWqEUlmP0np9HplCJ471y6y

    snOxXCZRyqOSx6+bCAXyFL1jQ434LkmIH6snjTfEuYt816aQuCinIgDyCvgtccmmiHCywGZhD6mP

    45oUSdPRqySy42FkC09wa68/urttvD6pWfAnAhTUnwIDAQABo4ICajCCAmYwDgYDVR0PAQH/BAQD

    AgWgMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFAl422hm60W2

    sj41v7T9ryc1JzNvMB8GA1UdIwQYMBaAFJjR+G4Q68+b7GCfGJAboOt9Cf0rMGQGCCsGAQUFBwEB

    BFgwVjAnBggrBgEFBQcwAYYbaHR0cDovL29jc3AucGtpLmdvb2cvZ3RzMW8xMCsGCCsGAQUFBzAC

    hh9odHRwOi8vcGtpLmdvb2cvZ3NyMi9HVFMxTzEuY3J0MC8GA1UdEQQoMCaCEGxvZ2luLmFwaWdl

    ZS5jb22CEioubG9naW4uYXBpZ2VlLmNvbTAhBgNVHSAEGjAYMAgGBmeBDAECAjAMBgorBgEEAdZ5

    AgUDMC8GA1UdHwQoMCYwJKAioCCGHmh0dHA6Ly9jcmwucGtpLmdvb2cvR1RTMU8xLmNybDCCAQQG

    CisGAQQB1nkCBAIEgfUEgfIA8AB1ALIeBcyLos2KIE6HZvkruYolIGdr2vpw57JJUy3vi5BeAAAB

    aE2wJd4AAAQDAEYwRAIgE5qO0j6O+mnFgQT5QV2005gT/z4Y9SwIFiJWyilYf+YCIBBwZ2ZvbWj8

    6EOLiwLhQvxV7o47q5TidaespugrwbCUAHcAXqdz+d9WwOe1Nkh90EngMnqRmgyEoRIShBh1loFx

    RVgAAAFoTbAl/gAABAMASDBGAiEAuUcc2S29sxMRcifJdHtls/zviIBlD7GNJJES7W3FzssCIQD9

    s1OqoMG5s9hD/OFOiNgLVg1Ga+Qvk+n4IRqAs00cdjANBgkqhkiG9w0BAQsFAAOCAQEAF2FfC4Gv

    4ialJOZZTZXk/hlXWJS8DZhxMLXT/cAzaJjtX64Ps2qY4xNSkuEmszVkwW4KdhKR1u+RGW6PRons

    0fC8rI4P1V6Ov6fq1WUeW2rQETzv+8riTbE9rvnKy2+0xscWvoEyGRK060TrMDFFHY5LI/jVCAIM

    bW1w1Tbopatc7dhWHbRtUUrTChOAS3AnGorXOsucoMzMW7aRxfmMg6HwRPA5jJyPU92wZJLLd3Py

    wLmvEQ3RzxCOoKtbZRM5XXZUmi6ptnyxV73hYjbPSpuv1UCT9AMmSnfrwi7bozz7/DzD9Kv8WES5

    GYUVaiD+1B4OZ8dT/qJ1VrA5ABiwVQ==</ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature><saml2:NameID xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified">Internal</saml2:NameID><saml2p:SessionIndex>o+3znHZ1nU6R0QDu5QA80xJiLv8=Lz1RnQ==</saml2p:SessionIndex></saml2p:LogoutRequest]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][doPostImpl][Relay State received={"redirect":"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","client_id":"portal-bnj0eaxbar"}]

    [12/11/2019][03:01:26][4866][140180963440384][][agentcommon][][Requesting data for ConfigManager ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/SmHost.conf and SmAgentConfig ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/WebAgent.conf]

    [12/11/2019][03:01:26][4866][140180963440384][][agentcommon][][Administration Manager is returning data for ConfigManager ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/SmHost.conf and SmAgentConfig ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/WebAgent.conf]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][handleLogout][RequestID: 11a64a58-dcb15741-353036e0-b24beec9-1b41fdf1-c2]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][handleLogout][RequestID 11a64a58-dcb15741-353036e0-b24beec9-1b41fdf1-c2 maps to TransactionID: 243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getSessionFromCookie][Fetching session details from cookie [CHECKPOINT = SLO_SESSION_FETCH]]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getSessionCookie][currentZone + Session cookie suffix: SMSESSION]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getSessionCookie][SMSESSION Cookie found.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][handleLogout][Reading session id from cookie data for session termination [CHECKPOINT = SLOSAML2_SESSIONIDFROMCOOKIEDATA_READ]]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][handleLogout][Warning: Length of Relay state {"redirect":"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","client_id":"portal-bnj0eaxbar"} is greater than 80 characters.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][handleLogout][Performing tunnel call for SAML1 SLO [CHECKPOINT = SLOSAML2_TUNNEL_REQUEST]]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][Retrieving the disambiguation ID from the requested URI /affwebservices/public/saml2slo]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][serviceURL=/public/saml2slo/]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][serviceURL /public/saml2slo/ not found in requestedURI /affwebservices/public/saml2slo]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][Retrieving the disambiguation ID from the requested URI /affwebservices/public/saml2slo]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][serviceURL=/public/saml2slosoap/]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][serviceURL /public/saml2slosoap/ not found in requestedURI /affwebservices/public/saml2slo]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SAMLTunnelClient.java][callSingleLogout][localURL: https://sitemindersps/affwebservices/public/saml2slo]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SAMLTunnelClient.java][callSingleLogout][Session ID: o+3znHZ1nU6R0QDu5QA80xJiLv8=.]

    [12/11/2019][03:01:26][4866][140180963440384][][agentcommon][][Requesting data for ConfigManager ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/SmHost.conf and SmAgentConfig ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/WebAgent.conf]

    [12/11/2019][03:01:26][4866][140180963440384][][agentcommon][][Administration Manager is returning data for ConfigManager ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/SmHost.conf and SmAgentConfig ID /opt/CA/secure-proxy/proxy-engine/conf/defaultagent/WebAgent.conf]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SAMLTunnelClient.java][callSingleLogout][Tunnel result code: 1.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][handleLogout][

    TUNNEL STATUS:

       status  : 0

       message : ]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][handleLogout][

    Output from Tunnel call:status=2&providerType=SP&providerID=ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login&SLOmessage=SAMLResponse=jZLNasMwEIRfxehuy%2FJfHGEbSnMJpJc65NBLkWXZVlAk1SvRPH4dh1B6CT0t7M58yw5bHcxovHsXYI0GEewEOKmZk0bXaHLOAsXYjF8j02Lw3ThIew6v55S5K2RWc0sm9R0xzo3XDiJm5ShEJA0GdlG4lXpU4r4CMyUZ%2FIO1IsKbP1RmlBoF%2B12NPrNkk3VxnPN8k%2BZ9ORQdGQQpslJsiy4e0i7N%2BkWqH6ccTY1YUk75IMs%2BLoY849m0zfJCkqlMimIqFzWAF3sNjmlXoyQm25AkISHHOKVxSZP8AwUnMcOaRhLFKLhelIYa%2BVlTw0AC1ewigDpO25e3A1001M7GGW4UaioNhK475ruRLo3nZgYg5lv6qDHWeQi5Mr4PZW8r%2FEtrqtaxZfqor6YXwYkpL57TYVXT1nMuABBuKvwA4b%2BP0PwA&RelayState={"redirect":"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","client_id":"portal-bnj0eaxbar"}&isPOST=false&isSOAPEnabled=false;relayState={"redirect":"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","client_id":"portal-bnj0eaxbar"}]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][handleSOAPLogout][ENTER:handleSOAPLogout]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][dispatchSOAPMessages][In dispatchSOAPMessages]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][dispatchSOAPMessages][Leaving dispatchSOAPMessages]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][handleSLORedirect][Entering handleSLORedirect]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][handleSLORedirect][SAMLSingleLogoutOutput: status=2&providerType=SP&providerID=ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login&SLOmessage=SAMLResponse=jZLNasMwEIRfxehuy%2FJfHGEbSnMJpJc65NBLkWXZVlAk1SvRPH4dh1B6CT0t7M58yw5bHcxovHsXYI0GEewEOKmZk0bXaHLOAsXYjF8j02Lw3ThIew6v55S5K2RWc0sm9R0xzo3XDiJm5ShEJA0GdlG4lXpU4r4CMyUZ%2FIO1IsKbP1RmlBoF%2B12NPrNkk3VxnPN8k%2BZ9ORQdGQQpslJsiy4e0i7N%2BkWqH6ccTY1YUk75IMs%2BLoY849m0zfJCkqlMimIqFzWAF3sNjmlXoyQm25AkISHHOKVxSZP8AwUnMcOaRhLFKLhelIYa%2BVlTw0AC1ewigDpO25e3A1001M7GGW4UaioNhK475ruRLo3nZgYg5lv6qDHWeQi5Mr4PZW8r%2FEtrqtaxZfqor6YXwYkpL57TYVXT1nMuABBuKvwA4b%2BP0PwA&RelayState={"redirect":"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","client_id":"portal-bnj0eaxbar"}&isPOST=false&isSOAPEnabled=false;relayState={"redirect":"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","client_id":"portal-bnj0eaxbar"}]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][dispatchOutputMessage][

    Number of processors: 1]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][dispatchOutputMessage][Sending LogoutResponse through sloProcessor.processOutputMessage]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][processOutputMessage][ENTER:processOutputMessage]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][Retrieving the disambiguation ID from the requested URI /affwebservices/public/saml2slo]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][serviceURL=/public/saml2slo/]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][serviceURL /public/saml2slo/ not found in requestedURI /affwebservices/public/saml2slo]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][Retrieving the disambiguation ID from the requested URI /affwebservices/public/saml2slo]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][serviceURL=/public/saml2slosoap/]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][getDisambiguationID][serviceURL /public/saml2slosoap/ not found in requestedURI /affwebservices/public/saml2slo]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][logoffSessionCookie][Logging out session cookie [CHECKPOINT = SLO_SESSIONCOOKIE_LOGOUT]]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][logoffSessionCookie][Issuing SMSESSION Cookie with value set to LOGGEDOFF.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][FWSBase.java][logoffSessionCookie][Issuing SESSIONSIGNOUT Cookie with value set to LOGGEDOFF.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][sendLogoutMessageToSP][Redirecting to service providers single logout service url [CHECKPOINT = SLOSAML2_SPSLOSERVICEURL_FORWARD]]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SAML2Base.java][getServiceProviderInfo][Trying to fetch SAML2.0 SP Configuration from cache [CHECKPOINT = SAML2_SPCONFFROMCACHE_REQ]]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SAML2Base.java][getServiceProviderInfo][Obtained service provider information from cache for: ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SAML2Base.java][getServiceProviderInfo][Obtained service provider information from cache for: ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][sendLogoutMessageUsingRedirect][ENTER: sendLogoutMessageUsingRedirect]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][sendLogoutMessageUsingRedirect][SLO Service URL: https://ogqganefubgfipj-xj3atxs4pncp1hlw.accounts.apigee.io/saml/SingleLogout/alias/ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][sendLogoutMessageUsingRedirect][SAML2 Single Logout Service redirecting to SP Single Logout Service URL: https://ogqganefubgfipj-xj3atxs4pncp1hlw.accounts.apigee.io/saml/SingleLogout/alias/ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login?SAMLResponse=jZLNasMwEIRfxehuy%2FJfHGEbSnMJpJc65NBLkWXZVlAk1SvRPH4dh1B6CT0t7M58yw5bHcxovHsXYI0GEewEOKmZk0bXaHLOAsXYjF8j02Lw3ThIew6v55S5K2RWc0sm9R0xzo3XDiJm5ShEJA0GdlG4lXpU4r4CMyUZ%2FIO1IsKbP1RmlBoF%2B12NPrNkk3VxnPN8k%2BZ9ORQdGQQpslJsiy4e0i7N%2BkWqH6ccTY1YUk75IMs%2BLoY849m0zfJCkqlMimIqFzWAF3sNjmlXoyQm25AkISHHOKVxSZP8AwUnMcOaRhLFKLhelIYa%2BVlTw0AC1ewigDpO25e3A1001M7GGW4UaioNhK475ruRLo3nZgYg5lv6qDHWeQi5Mr4PZW8r%2FEtrqtaxZfqor6YXwYkpL57TYVXT1nMuABBuKvwA4b%2BP0PwA&RelayState={"redirect":"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","client_id":"portal-bnj0eaxbar"}.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][doPost][Transaction with ID: 243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c failed. Reason: SLO_POST_EXCEPTION]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][doPost][The following error occured while processing request: java.net.URISyntaxException: Illegal character in query at index 610: https://ogqganefubgfipj-xj3atxs4pncp1hlw.accounts.apigee.io/saml/SingleLogout/alias/ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login?SAMLResponse=jZLNasMwEIRfxehuy%2FJfHGEbSnMJpJc65NBLkWXZVlAk1SvRPH4dh1B6CT0t7M58yw5bHcxovHsXYI0GEewEOKmZk0bXaHLOAsXYjF8j02Lw3ThIew6v55S5K2RWc0sm9R0xzo3XDiJm5ShEJA0GdlG4lXpU4r4CMyUZ%2FIO1IsKbP1RmlBoF%2B12NPrNkk3VxnPN8k%2BZ9ORQdGQQpslJsiy4e0i7N%2BkWqH6ccTY1YUk75IMs%2BLoY849m0zfJCkqlMimIqFzWAF3sNjmlXoyQm25AkISHHOKVxSZP8AwUnMcOaRhLFKLhelIYa%2BVlTw0AC1ewigDpO25e3A1001M7GGW4UaioNhK475ruRLo3nZgYg5lv6qDHWeQi5Mr4PZW8r%2FEtrqtaxZfqor6YXwYkpL57TYVXT1nMuABBuKvwA4b%2BP0PwA&RelayState={"redirect":"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","client_id":"portal-bnj0eaxbar"}.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][doPost][Stack Trace: java.lang.RuntimeException: java.net.URISyntaxException: Illegal character in query at index 610: https://ogqganefubgfipj-xj3atxs4pncp1hlw.accounts.apigee.io/saml/SingleLogout/alias/ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login?SAMLResponse=jZLNasMwEIRfxehuy%2FJfHGEbSnMJpJc65NBLkWXZVlAk1SvRPH4dh1B6CT0t7M58yw5bHcxovHsXYI0GEewEOKmZk0bXaHLOAsXYjF8j02Lw3ThIew6v55S5K2RWc0sm9R0xzo3XDiJm5ShEJA0GdlG4lXpU4r4CMyUZ%2FIO1IsKbP1RmlBoF%2B12NPrNkk3VxnPN8k%2BZ9ORQdGQQpslJsiy4e0i7N%2BkWqH6ccTY1YUk75IMs%2BLoY849m0zfJCkqlMimIqFzWAF3sNjmlXoyQm25AkISHHOKVxSZP8AwUnMcOaRhLFKLhelIYa%2BVlTw0AC1ewigDpO25e3A1001M7GGW4UaioNhK475ruRLo3nZgYg5lv6qDHWeQi5Mr4PZW8r%2FEtrqtaxZfqor6YXwYkpL57TYVXT1nMuABBuKvwA4b%2BP0PwA&RelayState={"redirect":"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","client_id":"portal-bnj0eaxbar"}

    at com.netegrity.affiliateminder.webservices.c.sendRedirect(fedfws_obfsc:56)

    at com.netegrity.affiliateminder.webservices.saml2.SLOService.a(fedfws_obfsc:2049)

    at com.netegrity.affiliateminder.webservices.saml2.SLOService.a(fedfws_obfsc:1964)

    at com.netegrity.affiliateminder.webservices.saml2.SLOService.b(fedfws_obfsc:1600)

    at com.netegrity.affiliateminder.webservices.f.a(fedfws_obfsc:2787)

    at com.netegrity.affiliateminder.webservices.saml2.SLOService.c(fedfws_obfsc:1327)

    at com.netegrity.affiliateminder.webservices.saml2.SLOService.a(fedfws_obfsc:1148)

    at com.netegrity.affiliateminder.webservices.saml2.SLOService.a(fedfws_obfsc:844)

    at com.netegrity.affiliateminder.webservices.saml2.SLOService.c(fedfws_obfsc:551)

    at com.netegrity.affiliateminder.webservices.saml2.SLOService.doPost(fedfws_obfsc:327)

    at javax.servlet.http.HttpServlet.service(HttpServlet.java:650)

    at javax.servlet.http.HttpServlet.service(HttpServlet.java:731)

    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:303)

    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)

    at com.netegrity.affiliateminder.webservices.CAFedFilter.doFilter(fedfws_obfsc:58)

    at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:241)

    at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)

    at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:219)

    at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:110)

    at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:494)

    at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:169)

    at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:113)

    at com.netegrity.proxy.ProxyValve.processRequest(Unknown Source)

    at com.netegrity.proxy.ProxyValve.invoke(Unknown Source)

    at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:116)

    at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:445)

    at org.apache.coyote.ajp.AjpProcessor.process(AjpProcessor.java:190)

    at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:637)

    at org.apache.tomcat.util.net.JIoEndpoint$SocketProcessor.run(JIoEndpoint.java:316)

    at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)

    at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)

    at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)

    at java.lang.Thread.run(Thread.java:748)

    Caused by: java.net.URISyntaxException: Illegal character in query at index 610: https://ogqganefubgfipj-xj3atxs4pncp1hlw.accounts.apigee.io/saml/SingleLogout/alias/ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login?SAMLResponse=jZLNasMwEIRfxehuy%2FJfHGEbSnMJpJc65NBLkWXZVlAk1SvRPH4dh1B6CT0t7M58yw5bHcxovHsXYI0GEewEOKmZk0bXaHLOAsXYjF8j02Lw3ThIew6v55S5K2RWc0sm9R0xzo3XDiJm5ShEJA0GdlG4lXpU4r4CMyUZ%2FIO1IsKbP1RmlBoF%2B12NPrNkk3VxnPN8k%2BZ9ORQdGQQpslJsiy4e0i7N%2BkWqH6ccTY1YUk75IMs%2BLoY849m0zfJCkqlMimIqFzWAF3sNjmlXoyQm25AkISHHOKVxSZP8AwUnMcOaRhLFKLhelIYa%2BVlTw0AC1ewigDpO25e3A1001M7GGW4UaioNhK475ruRLo3nZgYg5lv6qDHWeQi5Mr4PZW8r%2FEtrqtaxZfqor6YXwYkpL57TYVXT1nMuABBuKvwA4b%2BP0PwA&RelayState={"redirect":"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","client_id":"portal-bnj0eaxbar"}

    at java.net.URI$Parser.fail(URI.java:2848)

    at java.net.URI$Parser.checkChars(URI.java:3021)

    at java.net.URI$Parser.parseHierarchical(URI.java:3111)

    at java.net.URI$Parser.parse(URI.java:3053)

    at java.net.URI.<init>(URI.java:588)

    at com.netegrity.affiliateminder.webservices.c.sendRedirect(fedfws_obfsc:53)

    ... 32 more]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][doPost][Ending SAML2 Single Logout Service request processing.]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][sendSOAPFault][Sending SOAP fault message [CHECKPOINT = SLOSAML2_SOAPFAULT_SEND]]

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2a72-471d889f-1b1f6737-0c][SLOService.java][sendSOAPFault][Sending the following SOAP response message: <SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"><SOAP-ENV:Body><SOAP-ENV:Fault><faultcode>SOAP-ENV:Client</faultcode><faultstring>SOAP Processing Error. Exception processing request</faultstring></SOAP-ENV:Fault></SOAP-ENV:Body></SOAP-ENV:Envelope>.]

    [12/11/2019][03:01:30][4866][140181209335552][][agentcommon][][The Configuration Management thread is calling doManagement()]

    [12/11/2019][03:01:30][4866][140181209335552][][agentcommon][][There are doManagement messages]

    [12/11/2019][03:02:00][4866][140181034002176][][CustomPostPageCache][performUpdate][Checking for updates]

    [12/11/2019][03:02:00][4866][140181034002176][][CustomPostPageCache][performUpdate][Checking 1 cached pages for updates]

    [12/11/2019][03:02:00][4866][140181034002176][][CustomPostPageCache][performUpdate][Processing entry: ca-default-oidc-consent.html]

    [12/11/2019][03:02:00][4866][140181034002176][][CustomPostPageCache][performUpdate][



    ------------------------------
    Sasikumar
    ------------------------------


  • 2.  RE: SLO for SAML SP
    Best Answer

    Posted 12-11-2019 02:53 AM
    Hi Sasikumar,

    The traces reports the error :

    [12/11/2019][03:01:26][4866][140180963440384][243d9a0a-31388390-2b5a2
    a72-471d889f-1b1f6737-0c][SLOService.java][doPost][Stack
    Trace: java.lang.RuntimeException: java.net.URISyntaxException:
    Illegal character in query at index 610:

    Caused by: java.net.URISyntaxException: Illegal character in query at
    index 610:
    https://ogqganefubgfipj-xj3atxs4pncp1hlw.accounts.apigee.io/saml/Sing
    leLogout/alias/ogqganefubgfipj-xj3atxs4pncp1hlw.apigee-saml-login?SAM
    LResponse=jZLNasMwEIRfxehuy%2FJfHGEbSnMJpJc65NBLkWXZVlAk1SvRPH4dh1B6C
    T0t7M58yw5bHcxovHsXYI0GEewEOKmZk0bXaHLOAsXYjF8j02Lw3ThIew6v55S5K2RWc0
    sm9R0xzo3XDiJm5ShEJA0GdlG4lXpU4r4CMyUZ%2FIO1IsKbP1RmlBoF%2B12NPrNkk3V
    xnPN8k%2BZ9ORQdGQQpslJsiy4e0i7N%2BkWqH6ccTY1YUk75IMs%2BLoY849m0zfJCkq
    lMimIqFzWAF3sNjmlXoyQm25AkISHHOKVxSZP8AwUnMcOaRhLFKLhelIYa%2BVlTw0AC1
    ewigDpO25e3A1001M7GGW4UaioNhK475ruRLo3nZgYg5lv6qDHWeQi5Mr4PZW8r%2FEtr
    qtaxZfqor6YXwYkpL57TYVXT1nMuABBuKvwA4b%2BP0PwA&RelayState={"redirect"
    :"https://optus-enterprise-nonprod-optusinternal.apigee.io/logout","c
    lient_id":"portal-bnj0eaxbar"}

    The problem is that the RelayState value isn't URLEncoded.

    Question on RelayState

    When an SP includes a RelayState value in the query string as part
    of an authnrequest (SP-initiated request), the RelayState value must
    be URL-encoded.

    https://ca-broadcom.wolkenservicedesk.com/external/article?articleId=141295

    and

    Bindings for the OASIS Security Assertion Markup Language (SAML) V2.0

    3.4.3 RelayState

    RelayState data MAY be included with a SAML protocol message
    transmitted with this binding. The value MUST NOT exceed 80 bytes in
    length and SHOULD be integrity protected by the entity creating the
    message independent of any other protections that may or may not exist
    during message transmission.

    3.4.4 Message Encoding

    Messages are encoded for use with this binding using a URL encoding
    technique, and transmitted using the HTTP GET method.

    https://docs.oasis-open.org/security/saml/v2.0/saml-bindings-2.0-os.pdf

    Best Regards,
    Patrick


  • 3.  RE: SLO for SAML SP

    Posted 6 days ago
    Hello Patrick,

    Thank you for your input.

    Please note, this is logout request with the post binding. do we have an option to ignore relay state ?

    THanks
    Sasi


  • 4.  RE: SLO for SAML SP

    Posted 6 days ago
    Hi Sasi,

    In order to ignore the RelayState, you have to configure the SP to not
    send it.

    I hope this helps,

    Best Regards,
    Patrick