OpenIDC / mod_auth_openidc

OpenID Certified™ OpenID Connect Relying Party implementation for Apache HTTP Server 2.x
Apache License 2.0
975 stars 325 forks source link

Password prompts on O365 user devices #155

Closed mailugk closed 8 years ago

mailugk commented 8 years ago

Users are seeing Password prompts on O365 user devices nothing changed as far as credentials , and they just choose Cancel and mail continues to flow. We are seeing below error messages in Ping Audit.log-

2016-07-25 14:47:05,229|STS| abc@xyz.com| 3.203.X.X | | urn:federation:MicrosoftOnline| WSTrust| server1.cloud.com| IdP| failure| | Invalid Token: Authentication failed: Invalid Credentials| 36

Below is the snippet from server.log-

016-07-25 14:48:36,557 tid:Pa8_LVwkB5djCMJyRiyzhEjzx8I DEBUG [org.sourceid.saml20.bindings.LoggingInterceptor] Handle Exception (http://www.w3.org/2003/05/soap-envelope). org.sourceid.wstrust.handlers.WSTrustException: Invalid Token: Authentication failed: Invalid Credentials at org.sourceid.wstrust.handlers.TokenPluginSupport.processToken(TokenPluginSupport.java:114) ~[pf-protocolengine.jar:?] at org.sourceid.wstrust.handlers.TokenPluginSupport.processToken(TokenPluginSupport.java:77) ~[pf-protocolengine.jar:?] at org.sourceid.wstrust.handlers.IdpWSTrustRequestHandler.handleIssueRequest(IdpWSTrustRequestHandler.java:137) ~[pf-protocolengine.jar:?] at org.sourceid.wstrust.handlers.WSTrustBaseRequestHandler.process(WSTrustBaseRequestHandler.java:162) ~[pf-protocolengine.jar:?] at org.sourceid.saml20.profiles.ProfileProcessManager.doHandleRequest(ProfileProcessManager.java:77) ~[pf-protocolengine.jar:?] at $ProfileProcessMgmtService_155f42b88a6.doHandleRequest($ProfileProcessMgmtService_155f42b88a6.java) ~[?:?] at org.sourceid.websso.servlet.ProtocolControllerServlet.doIt(ProtocolControllerServlet.java:103) ~[pf-protocolengine.jar:?] at org.sourceid.websso.servlet.ProtocolControllerServlet.process(ProtocolControllerServlet.java:123) ~[pf-protocolengine.jar:?]

What can be the cause?

Thanks,

zandbelt commented 8 years ago

this is not a question about mod_auth_openidc; you should take it up on the Ping Identity support channel(s) for PingFederate