<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
There shouldn't be any additional requirements, and in fact 1.1.12 should work significantly better out of the box compared to 1.1.3, which had several large known issues. Are you able to log into the server directly, without using the authorization page? It
 sounds like there could be something going on with your LDAP connection that's preventing it from completing the transaction. Is there anything in your server logs that could indicate a crash or problem on the server?
<div><br>
</div>
<div>Also, which client software are you using? I'm assuming it's the same for both cases.<br>
<div><br>
</div>
<div>&nbsp;-- Justin</div>
<div><br>
<div>
<div>On Dec 18, 2014, at 11:13 AM, Felipe Polo-Wood &lt;<a href="mailto:felipe.polowood@duke.edu">felipe.polowood@duke.edu</a>&gt; wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite"><style type="text/css" style="display:none"><!-- p { margin-top: 0px; margin-bottom: 0px; }--></style>
<div dir="ltr">
<div id="divtagdefaultwrapper" style="font-size: 12pt; background-color: rgb(255, 255, 255); font-family: Inconsolata;">
<div><br class="webkit-block-placeholder">
</div>
<p class="p1"><span class="s1">We were having problems with 1.1.3 and it was suggested to upgrade to 1.1.12. &nbsp;We haven't had much success, so I decided to run some tests in a very clean scenario with as little change as possible. &nbsp;So, here it is:</span></p>
<p class="p1"><span class="s1"><br>
</span></p>
<p class="p1"><span class="s1">I took a vainilla 1.1.3 and made one simple change to the sample client: add
<a href="http://www.duke.edu/" id="lnk147249">http://www.duke.edu</a> as a redirect. &nbsp;I then whitelisted the client.</span></p>
<p class="p1"><span style="font-size: 12pt;">When calling&nbsp;</span><span style="font-size: 12pt;"><a href="http://xxx/ldap-openid-connect-server-113/authorize?client_id=client&amp;redirect_uri=http://www.duke.edu&amp;scope=openid%20profile&amp;response_type=code" id="lnk507984">http://xxx/ldap-openid-connect-server-113/authorize?client_id=client&amp;redirect_uri=http://www.duke.edu&amp;scope=openid%20profile&amp;response_type=code</a>&nbsp;</span><span style="font-size: 12pt;">it&nbsp;</span><span style="font-size: 12pt;">prompts
 me f</span><span style="font-size: 12pt;">or credentials and then redirects&nbsp;me to
</span><a href="http://www.duke.edu/?code=xxxxxxx" id="lnk660789" style="font-size: 12pt;">http://www.duke.edu/?code=xxxxxxx</a><span style="font-size: 12pt;">​&nbsp;</span></p>
<p class="p1"><span class="s1"></span><span style="font-size: 12pt;">Subsequent ac</span><span style="font-size: 12pt;">cess sends me directly w/o prompting for credentials.</span></p>
<p class="p1"><span style="font-size: 12pt;">On the management page it shows &quot;</span><span style="font-size: 12pt;">There have been&nbsp;1&nbsp;user of this system who have logged in to&nbsp;1&nbsp;total site, for a total of&nbsp;1&nbsp;site approval&quot;&nbsp;</span><span style="font-size: 12pt;">and
 the client shows up </span><span style="font-size: 12pt;">in the&nbsp;“Manage Approved Sites” page.</span></p>
<p class="p2"><span class="s1"></span><br>
</p>
<p class="p1"><span class="s1">When trying to repeat that simple scenario&nbsp;in 1.1.12... added the redirect and whitelisted the client.</span></p>
<p class="p1"><span class="s1"></span><span style="font-size: 12pt;"><a href="http://vml-catstools2:8080/ldap-openid-connect-server/authorize?client_id=client&amp;redirect_uri=theclient://callback&amp;scope=openid%20profile&amp;response_type=code" id="lnk509122">http://xxx/ldap-openid-connect-server/authorize?client_id=client&amp;redirect_uri=http://www.duke.edu&amp;scope=openid%20profile&amp;response_type=code</a>
 it&nbsp;</span><span style="font-size: 12pt;">prompts me for credentials every time and after the credentials it redirects&nbsp;me to the
<a href="http://xxx/ldap-openid-">http://xxx/ldap-openid-</a></span><span style="font-size: 12pt;">connect-server management&nbsp;page, where it displays &quot;</span><span style="font-size: 12pt;">There hav</span><span style="font-size: 12pt;">e been&nbsp;0&nbsp;users&nbsp;of this
 system who have authorized&nbsp;0&nbsp;applications, with a total of&nbsp;0&nbsp;site&nbsp;approvals&quot; and the client never shows up in the &quot;Manage Approved Sites&quot; page.<br>
</span></p>
<p class="p1"><span style="font-size: 12pt;"><br>
</span></p>
<p class="p1">Was there some change that requires some extra step or configuration for this simple scenario to work on 1.1.12?<br>
</p>
<p class="p1"><br>
</p>
<p class="p1">Thanks,<br>
</p>
<p><br>
</p>
<p><br>
</p>
<div id="Signature">
<div name="divtagdefaultwrapper" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:; margin:0">
<div style="font-size:13px; font-family:Tahoma">
<div class="BodyFragment"><font size="2">
<div class="PlainText">Felipe Polo-Wood<br>
Sr. Manager<br>
Clinical Applications Technical Services</div>
<div class="PlainText">Office: &#43;1.919.668.2268<br>
Mobile: &#43;1.919.741.4213<br>
</div>
</font></div>
</div>
</div>
</div>
</div>
</div>
_______________________________________________<br>
mitreid-connect mailing list<br>
<a href="mailto:mitreid-connect@mit.edu">mitreid-connect@mit.edu</a><br>
http://mailman.mit.edu/mailman/listinfo/mitreid-connect<br>
</blockquote>
</div>
<br>
</div>
</div>
</body>
</html>