- ID
- 394f572d-17a2-4434-8123-8da926985aa9
- ROAM_ALIASES
- ENG-14696
ENG-14696 - Spike: JJenkins@rivermarkcu.org cannot log in - 400 error
- tags :: Jira SAML/SCIM 15Five
Description
Issue: Joel Jenkins is getting a 400 error when he tries to log into 15Five via SSO. He's the only one in the company who is having login issues.
Joel is using the email address we have on file for him (JJenkins@rivermarkcu.org) and is logging in at the right domain (https://rivermarkcu.15five.com). Here's a screenshot from within Azure showing that the same email address is set there as in 15Five:
The company uses Azure for SSO. Here's their SAML configuration in Django. The company admin I’m talking to said that Azure shows that the connection was successful.
If you search through SAML response records for Joel's email address, nothing appears. But you can see in the company's SAML response records that someone is getting 400 errors when trying to log in:
Joel has been active in 15Five since 4/15/20 and didn't experience any login issues until recently. The last time he was able to log into 15Five was in December 2020. I don't see any changes in his user history that would cause login issues. After comparing Joel's Django user page info to that of a user who is able to log in without issue Meilena tried changing his SCIM ID from lowercase to uppercase in case it was case sensitive. That did not work.
Expected behavior: Joel can log into 15Five via SSO.
Impacted user: Joel Jenkins - 1638196 - JJenkins@rivermarkcu.org
Company info: Rivermark CCU - 50442 - 281 active users
Intercom ticket: https://app.intercom.com/a/apps/i57gzr9/inbox/inbox/2912106/conversations/112000270275
Debug info
+ Krystian Cybulski's comment
#+begin_quote
the nameID is passed but not extracted for JJ.
We see a similar situation for tmeskal@….
NameID extracted
NameID did not get extracted
Once we understand how these two SAMLResponses were handled differently, we’ll have a clue to this issue.
#+end_quote
+ [[https://kibana.cloud100.15five.com/app/kibana#/discover?_g=(refreshInterval:(pause:!t,value:0),time:(from:now-6M,mode:quick,to:now))&_a=(columns:!(request_method,message,response_status_code),index:'132f6850-b324-11ea-8c9b-77a5cb38c6d7',interval:auto,query:(language:lucene,query:JJenkins),sort:!('@timestamp',desc))][Kibana logs for JJenkins]]
+ [[https://kibana.cloud100.15five.com/app/kibana#/discover?_g=(refreshInterval:(pause:!t,value:0),time:(from:now-6M,mode:quick,to:now))&_a=(columns:!(request_method,message,response_status_code),index:'132f6850-b324-11ea-8c9b-77a5cb38c6d7',interval:auto,query:(language:lucene,query:'%22jwinslow@rivermarkcu.org%22%20%22JJenkins@rivermarkcu.org%22%20%22sbritton@rivermarkcu.org%22%20%22SVadakumacherry@rivermarkcu.org%22%20%22bsmith@rivermarkcu.org%22%20%22BGriffis@rivermarkcu.org%22%20%22ABurhyte@rivermarkcu.org%22%20%22DNoble@rivermarkcu.org%22'),sort:!('@timestamp',desc))][Kibana Logs for other users with 400 errors]]
#+begin_src xml XML response to failure
<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" ID="_8d108504-3b4b-4223-87b9-3c009bcfd318" Version="2.0" IssueInstant="2021-01-25T16:32:13.040Z" Destination="https://rivermarkcu.15five.com/saml2/acs/" InResponseTo="ONELOGIN_3eef757f11a1052680137695ec46182b24f55916">
<Issuer xmlns="urn:oasis:names:tc:SAML:2.0:assertion">https://sts.windows.net/c926e4a0-b4da-420d-abf0-25d1c304681a/</Issuer>
<Signature xmlns="http://www.w3.org/2000/09/xmldsig#">
<SignedInfo>
<CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
<SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<Reference URI="#_8d108504-3b4b-4223-87b9-3c009bcfd318">
<Transforms>
<Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</Transforms>
<DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<DigestValue>rjuXd5xuwICfgIkAPMvyl2eAJtVYzpzigEAeTYB6wv8=</DigestValue>
</Reference>
</SignedInfo>
<SignatureValue>bppNDAJEeWf6En5uMCRns1dDsiUqXxddo8QTYBXmgZD5AAUocbOqtYLd1Kbs4B/EJcaycGpHQZCglUptkM5GTett1dUbHnS6ozhMFfLqzNVkYmUlWCP5RvQ491gZMEku0K+liK+CpR1Xk0NA8A28xyfRgQI8I23cFgJ8WUekpWz+0Oc4G00GDmEWyN5W1qfd1rXtg5iJg5nAffUgIsLSdaRhLXYHXftgzA2CVt1L5Pvg2PfTBMiTWe234KYb2N4fckxLqtq6wuQT+U2reU0/9faYf0kFKGR4vjL/4o4nmrVHYJnD8uEd1gLcsJ14LnXnb4u1l/aYw/pRIRbo2GhpUQ==</SignatureValue>
<KeyInfo>
<ds:X509Data xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Certificate>MIIC8DCCAdigAwIBAgIQKJ5YA16wNqhHulzrRYFTgjANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMDA0MDkxODU4MDhaFw0yMzA0MDkxODU4MDhaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA63SFpRaVEeAPMTt2HKIlS71e1IC+8H+08b7bS1WeK9FJLt9iKo3TJP9pqf9HPjsIXZm5a6VBhqS8csr1QFsJjz7qKn2wMlCvfRyOe23cfZHA/DRBXe4Mr/vOTuNDG+8H6+yLoqJ3MaL+BuzM6/TASq61nPLvfoFM058ZPzouBK6riM3kvA8dOh/h+SvA58tW0Zoffd2/g2SbvfWEnxF3RJc0UTHMIaNSO79CfA2wvlgm+UBSkeArF94OeI7l4ig3FEhiaUdGzQSO+/Bj2X82fvFcf9JvxVJuy7tej4HkVAM+2pgGMjFhOmL/Iii446f7yYdbzRdFp11nXKC6rNHs/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQCgxdBcRh9/LObv0GwzMAUJq2S8v5+LUy/EfcL0yrPHgl5NB30c3CqXdc974yjtEpM0D3jwvWpkq0sQJb2/XY1B3iufb4hN974tgb7tymjat+B/6lA5QFkSU6JTtH3nOkufur0b2D7UqFwIXtyfEJItLyJKpJZDUsk3ajOyUBoUYriUU99SGcRlQFuRx2107dSBK/SO1B93bBKwKXO5ipM101U+Jstquru//fgV0RUaM9w92aHgsyRuR9P769GFxLC7h8+uiKix7n6l34+ZG3wMf6ogDJ5F+b3EYWdYrkZyDVFiVGMs75muo3MgvKhWnkE7h7f+OQcGKEn5l5i1K1rC</ds:X509Certificate>
</ds:X509Data>
</KeyInfo>
</Signature>
<samlp:Status>
<samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
</samlp:Status>
<Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion" ID="_7301cef7-f713-4250-8e76-30e300493a00" IssueInstant="2021-01-25T16:32:13.040Z" Version="2.0">
<Issuer>https://sts.windows.net/c926e4a0-b4da-420d-abf0-25d1c304681a/</Issuer>
<Subject>
<NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">tmeskel@rivermarkcu.org</NameID>
<SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
<SubjectConfirmationData InResponseTo="ONELOGIN_3eef757f11a1052680137695ec46182b24f55916" NotOnOrAfter="2021-01-25T17:32:12.955Z" Recipient="https://rivermarkcu.15five.com/saml2/acs/"/>
</SubjectConfirmation>
</Subject>
<Conditions NotBefore="2021-01-25T16:27:12.955Z" NotOnOrAfter="2021-01-25T17:32:12.955Z">
<AudienceRestriction>
<Audience>https://rivermarkcu.15five.com/saml2/metadata/</Audience>
</AudienceRestriction>
</Conditions>
<AttributeStatement>
<Attribute Name="http://schemas.microsoft.com/identity/claims/tenantid">
<AttributeValue>c926e4a0-b4da-420d-abf0-25d1c304681a</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.microsoft.com/identity/claims/objectidentifier">
<AttributeValue>a64f5577-2c38-425d-8ec9-1ca3b0d2c439</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.microsoft.com/identity/claims/displayname">
<AttributeValue>Teresa Meskel</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.microsoft.com/identity/claims/identityprovider">
<AttributeValue>https://sts.windows.net/c926e4a0-b4da-420d-abf0-25d1c304681a/</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.microsoft.com/claims/authnmethodsreferences">
<AttributeValue>http://schemas.microsoft.com/ws/2008/06/identity/authenticationmethod/password</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname">
<AttributeValue>Teresa</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname">
<AttributeValue>Meskel</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress">
<AttributeValue>tmeskel@rivermarkcu.org</AttributeValue>
</Attribute>
<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name">
<AttributeValue>tmeskel@rivermarkcu.org</AttributeValue>
</Attribute>
</AttributeStatement>
<AuthnStatement AuthnInstant="2021-01-22T22:21:29.000Z" SessionIndex="_7301cef7-f713-4250-8e76-30e300493a00">
<AuthnContext>
<AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</AuthnContextClassRef>
</AuthnContext>
</AuthnStatement>
</Assertion>
</samlp:Response>
#+end_src