Help:Interinstitutional Authentication Problem Solving
From GPNWiki
Contents |
Framework
Note: Works means successful user authentication
| Service Provider | |||||
|---|---|---|---|---|---|
| Site A | Site B | Site C | Site D | ||
| Insititution A | Works/Not | Works/Not | Works/Not | Works/Not | |
| Insititution B | Works/Not | Works/Not | Works/Not | Works/Not | |
| ID Provider (Authenticates User) | Insititution C | Works/Not | Works/Not | Works/Not | Works/Not |
| Insititution D | Works/Not | Works/Not | Works/Not | Works/Not | |
| Insititution E | Works/Not | Works/Not | Works/Not | Works/Not |
I suggest that by knowing what works and what doesn't work, it is possible to tease out the source of the problem.
With only two ID Providers or only two services, it may be necessary to add an additional one into the mix
Example 1
| Service | |||
|---|---|---|---|
| GPN Wiki | UM Repository | ||
| ID Provider (Authenticates User) | GPN | Works | Not |
| KU | Works | Not | |
| UM-Gordon | Works | Not | |
| UM-System | Works | Not |
This would probably indicate that something is not right on the UM Repository
Example 2
| Service | |||
|---|---|---|---|
| GPN Wiki | UM Repository | ||
| ID Provider (Authenticates User) | GPN | Works | Works |
| KU | Works | Works | |
| UM-Gordon | Not | Not | |
| UM-System | Works | Works |
This would seem to indicate that the problem is the UM (Gordon's) Identity Provider
Example 3
| Service | |||
|---|---|---|---|
| GPN Wiki | UM Repository | ||
| ID Provider (Authenticates User) | GPN | Works | Works |
| KU | Works | Not | |
| UM-Gordon | Works | Works | |
| UM-System | Not | Works |
This could indicate two separate problems, but not necessarily indicate the source of the problem
Might have to add a third SP to see what is going on.
State of GPN Shibboleth
| Service | |||
|---|---|---|---|
| GPN Wiki | UM Repository | ||
| ID Provider (Authenticates User) | GPN | Works | Works |
| KU | Works | Not | |
| UM-Gordon | Works | Works | |
| UM-System | Does not pass attributes, establishes anonymous session | Works |
