Org Web Adapter

pages/eng_14696_spike_jjenkins_rivermarkcu_org_cannot_log_in_400_error.org

ID
394f572d-17a2-4434-8123-8da926985aa9
ROAM_ALIASES
ENG-14696

ENG-14696 - Spike: JJenkins@rivermarkcu.org cannot log in - 400 error

- tags :: Jira SAML/SCIM 15Five

Description

Issue: Joel Jenkins is getting a 400 error when he tries to log into 15Five via SSO. He's the only one in the company who is having login issues.

Joel is using the email address we have on file for him (JJenkins@rivermarkcu.org) and is logging in at the right domain (https://rivermarkcu.15five.com). Here's a screenshot from within Azure showing that the same email address is set there as in 15Five:

The company uses Azure for SSO. Here's their SAML configuration in Django. The company admin I’m talking to said that Azure shows that the connection was successful.

If you search through SAML response records for Joel's email address, nothing appears. But you can see in the company's SAML response records that someone is getting 400 errors when trying to log in:

Joel has been active in 15Five since 4/15/20 and didn't experience any login issues until recently. The last time he was able to log into 15Five was in December 2020. I don't see any changes in his user history that would cause login issues. After comparing Joel's Django user page info to that of a user who is able to log in without issue Meilena tried changing his SCIM ID from lowercase to uppercase in case it was case sensitive. That did not work.

Expected behavior: Joel can log into 15Five via SSO.

Impacted user: Joel Jenkins - 1638196 - JJenkins@rivermarkcu.org

Company info: Rivermark CCU - 50442 - 281 active users

Intercom ticket: https://app.intercom.com/a/apps/i57gzr9/inbox/inbox/2912106/conversations/112000270275

Debug info

+ Krystian Cybulski's comment

#+begin_quote

the nameID is passed but not extracted for JJ.

We see a similar situation for tmeskal@….

NameID extracted

NameID did not get extracted

Once we understand how these two SAMLResponses were handled differently, we’ll have a clue to this issue.

#+end_quote

+ [[https://kibana.cloud100.15five.com/app/kibana#/discover?_g=(refreshInterval:(pause:!t,value:0),time:(from:now-6M,mode:quick,to:now))&_a=(columns:!(request_method,message,response_status_code),index:'132f6850-b324-11ea-8c9b-77a5cb38c6d7',interval:auto,query:(language:lucene,query:JJenkins),sort:!('@timestamp',desc))][Kibana logs for JJenkins]]

+ [[https://kibana.cloud100.15five.com/app/kibana#/discover?_g=(refreshInterval:(pause:!t,value:0),time:(from:now-6M,mode:quick,to:now))&_a=(columns:!(request_method,message,response_status_code),index:'132f6850-b324-11ea-8c9b-77a5cb38c6d7',interval:auto,query:(language:lucene,query:'%22jwinslow@rivermarkcu.org%22%20%22JJenkins@rivermarkcu.org%22%20%22sbritton@rivermarkcu.org%22%20%22SVadakumacherry@rivermarkcu.org%22%20%22bsmith@rivermarkcu.org%22%20%22BGriffis@rivermarkcu.org%22%20%22ABurhyte@rivermarkcu.org%22%20%22DNoble@rivermarkcu.org%22'),sort:!('@timestamp',desc))][Kibana Logs for other users with 400 errors]]

#+begin_src xml XML response to failure

<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" ID="_8d108504-3b4b-4223-87b9-3c009bcfd318" Version="2.0" IssueInstant="2021-01-25T16:32:13.040Z" Destination="https://rivermarkcu.15five.com/saml2/acs/" InResponseTo="ONELOGIN_3eef757f11a1052680137695ec46182b24f55916">

<Issuer xmlns="urn:oasis:names:tc:SAML:2.0:assertion">https://sts.windows.net/c926e4a0-b4da-420d-abf0-25d1c304681a/</Issuer>

<Signature xmlns="http://www.w3.org/2000/09/xmldsig#">

<SignedInfo>

<CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>

<SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>

<Reference URI="#_8d108504-3b4b-4223-87b9-3c009bcfd318">

<Transforms>

<Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>

<Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>

</Transforms>

<DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>

<DigestValue>rjuXd5xuwICfgIkAPMvyl2eAJtVYzpzigEAeTYB6wv8=</DigestValue>

</Reference>

</SignedInfo>

<SignatureValue>bppNDAJEeWf6En5uMCRns1dDsiUqXxddo8QTYBXmgZD5AAUocbOqtYLd1Kbs4B/EJcaycGpHQZCglUptkM5GTett1dUbHnS6ozhMFfLqzNVkYmUlWCP5RvQ491gZMEku0K+liK+CpR1Xk0NA8A28xyfRgQI8I23cFgJ8WUekpWz+0Oc4G00GDmEWyN5W1qfd1rXtg5iJg5nAffUgIsLSdaRhLXYHXftgzA2CVt1L5Pvg2PfTBMiTWe234KYb2N4fckxLqtq6wuQT+U2reU0/9faYf0kFKGR4vjL/4o4nmrVHYJnD8uEd1gLcsJ14LnXnb4u1l/aYw/pRIRbo2GhpUQ==</SignatureValue>

<KeyInfo>

<ds:X509Data xmlns:ds="http://www.w3.org/2000/09/xmldsig#">

<ds:X509Certificate>MIIC8DCCAdigAwIBAgIQKJ5YA16wNqhHulzrRYFTgjANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMDA0MDkxODU4MDhaFw0yMzA0MDkxODU4MDhaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA63SFpRaVEeAPMTt2HKIlS71e1IC+8H+08b7bS1WeK9FJLt9iKo3TJP9pqf9HPjsIXZm5a6VBhqS8csr1QFsJjz7qKn2wMlCvfRyOe23cfZHA/DRBXe4Mr/vOTuNDG+8H6+yLoqJ3MaL+BuzM6/TASq61nPLvfoFM058ZPzouBK6riM3kvA8dOh/h+SvA58tW0Zoffd2/g2SbvfWEnxF3RJc0UTHMIaNSO79CfA2wvlgm+UBSkeArF94OeI7l4ig3FEhiaUdGzQSO+/Bj2X82fvFcf9JvxVJuy7tej4HkVAM+2pgGMjFhOmL/Iii446f7yYdbzRdFp11nXKC6rNHs/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQCgxdBcRh9/LObv0GwzMAUJq2S8v5+LUy/EfcL0yrPHgl5NB30c3CqXdc974yjtEpM0D3jwvWpkq0sQJb2/XY1B3iufb4hN974tgb7tymjat+B/6lA5QFkSU6JTtH3nOkufur0b2D7UqFwIXtyfEJItLyJKpJZDUsk3ajOyUBoUYriUU99SGcRlQFuRx2107dSBK/SO1B93bBKwKXO5ipM101U+Jstquru//fgV0RUaM9w92aHgsyRuR9P769GFxLC7h8+uiKix7n6l34+ZG3wMf6ogDJ5F+b3EYWdYrkZyDVFiVGMs75muo3MgvKhWnkE7h7f+OQcGKEn5l5i1K1rC</ds:X509Certificate>

</ds:X509Data>

</KeyInfo>

</Signature>

<samlp:Status>

<samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>

</samlp:Status>

<Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion" ID="_7301cef7-f713-4250-8e76-30e300493a00" IssueInstant="2021-01-25T16:32:13.040Z" Version="2.0">

<Issuer>https://sts.windows.net/c926e4a0-b4da-420d-abf0-25d1c304681a/</Issuer>

<Subject>

<NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">tmeskel@rivermarkcu.org</NameID>

<SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">

<SubjectConfirmationData InResponseTo="ONELOGIN_3eef757f11a1052680137695ec46182b24f55916" NotOnOrAfter="2021-01-25T17:32:12.955Z" Recipient="https://rivermarkcu.15five.com/saml2/acs/"/>

</SubjectConfirmation>

</Subject>

<Conditions NotBefore="2021-01-25T16:27:12.955Z" NotOnOrAfter="2021-01-25T17:32:12.955Z">

<AudienceRestriction>

<Audience>https://rivermarkcu.15five.com/saml2/metadata/</Audience>

</AudienceRestriction>

</Conditions>

<AttributeStatement>

<Attribute Name="http://schemas.microsoft.com/identity/claims/tenantid">

<AttributeValue>c926e4a0-b4da-420d-abf0-25d1c304681a</AttributeValue>

</Attribute>

<Attribute Name="http://schemas.microsoft.com/identity/claims/objectidentifier">

<AttributeValue>a64f5577-2c38-425d-8ec9-1ca3b0d2c439</AttributeValue>

</Attribute>

<Attribute Name="http://schemas.microsoft.com/identity/claims/displayname">

<AttributeValue>Teresa Meskel</AttributeValue>

</Attribute>

<Attribute Name="http://schemas.microsoft.com/identity/claims/identityprovider">

<AttributeValue>https://sts.windows.net/c926e4a0-b4da-420d-abf0-25d1c304681a/</AttributeValue>

</Attribute>

<Attribute Name="http://schemas.microsoft.com/claims/authnmethodsreferences">

<AttributeValue>http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/password</AttributeValue>

</Attribute>

<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname">

<AttributeValue>Teresa</AttributeValue>

</Attribute>

<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname">

<AttributeValue>Meskel</AttributeValue>

</Attribute>

<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress">

<AttributeValue>tmeskel@rivermarkcu.org</AttributeValue>

</Attribute>

<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name">

<AttributeValue>tmeskel@rivermarkcu.org</AttributeValue>

</Attribute>

</AttributeStatement>

<AuthnStatement AuthnInstant="2021-01-22T22:21:29.000Z" SessionIndex="_7301cef7-f713-4250-8e76-30e300493a00">

<AuthnContext>

<AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</AuthnContextClassRef>

</AuthnContext>

</AuthnStatement>

</Assertion>

</samlp:Response>

#+end_src