Hub healthy IdP healthy 1 audit warning Refresh

Journey diagnostics

jrn_u8seQc7WSYZHxqBv-k3drWFu

Timeline, grouped protocol exchanges and session impact stay correlated under the same run.

Status

OK

Timeline combines IAM Lab events and redacted PingFederate log events pushed by the future local Mint agent.

Evidence

Events
2
First KO
None
Sources
sp_app

Grouped exchanges

Timeline JSONRaw events JSON

sp_app · saml-a

AuthnRequest · saml-a -> hub

OK
sp_app · saml-a
SAML_AUTHN_REQUEST_CREATEDsaml-a -> hub
AuthnRequest
Message
AuthnRequest
ID
_C0_9sZYXPU2PFeUPTU5yqY-eFEGmia68
Destination
https://hub.sabathe.eu/idp/SSO.saml2
IssueInstant
2026-07-20T15:46:41Z
Version
2.0
Issuer
https://saml-a.sabathe.eu/metadata
<?xml version="1.0" ?>
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="_C0_9sZYXPU2PFeUPTU5yqY-eFEGmia68" Version="2.0" IssueInstant="2026-07-20T15:46:41Z" Destination="https://hub.sabathe.eu/idp/SSO.saml2" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" AssertionConsumerServiceURL="https://saml-a.sabathe.eu/saml/acs">
  <saml:Issuer>https://saml-a.sabathe.eu/metadata</saml:Issuer>
  <samlp:NameIDPolicy Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" AllowCreate="true"/>
</samlp:AuthnRequest>
SUCCESS

sp_app · saml-a

Response · hub -> saml-a

OK
sp_app · saml-a
SAML_RESPONSE_RECEIVEDhub -> saml-a
Response
Message
Response
ID
oQS0VDP1YXbSIehlOtygYh.yzJW
InResponseTo
_C0_9sZYXPU2PFeUPTU5yqY-eFEGmia68
Destination
https://saml-a.sabathe.eu/saml/acs
IssueInstant
2026-07-20T15:46:43.381Z
Version
2.0
Issuer
https://hub.sabathe.eu
StatusCode
urn:oasis:names:tc:SAML:2.0:status:Success
Assertion ID
EPiJS.ZajyIYxSbKro.ZRC5FsZf
NameID
user1
SessionIndex
EPiJS.ZajyIYxSbKro.ZRC5FsZf
Audience
https://saml-a.sabathe.eu/metadata
<?xml version="1.0" ?>
<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" Version="2.0" ID="oQS0VDP1YXbSIehlOtygYh.yzJW" IssueInstant="2026-07-20T15:46:43.381Z" InResponseTo="_C0_9sZYXPU2PFeUPTU5yqY-eFEGmia68" Destination="https://saml-a.sabathe.eu/saml/acs">
  <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://hub.sabathe.eu</saml:Issuer>
  <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
    <ds:SignedInfo>
      <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
      <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
      <ds:Reference URI="#oQS0VDP1YXbSIehlOtygYh.yzJW">
        <ds:Transforms>
          <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
          <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
        </ds:Transforms>
        <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
        <ds:DigestValue>Q0VYKSJDxI9gWNWHK3Gy6xsvQiO/TS0nchZLcmVf1fE=</ds:DigestValue>
      </ds:Reference>
    </ds:SignedInfo>
    <ds:SignatureValue>TLbwTNDMaPp/85EG96GmNa6f8fUwuq42QlESAP8VV8b1OBKqYUw/Ce16qgg4JIptJ0EQPGDzwMLVVZaiuzS+e2mJXjfkchbOb7ABrokGT5mGcKE6X8K/7PQ2LJ7bYjzIilaS+lsw6DwrMeXiV6+CJf2z35unHvBxzlZsSEK25Cb7zwQKU22CR0WdKJk4Pm9Q91ytn/yh6AYWYDEfKZBrPHVYuop7cpywMb4mUnvEL1oPF4Z/iIJPIzKEgDkdtu1V49OH6OHxFmd+u4dyhV64FrwEszisHv+1PD6YhMwJuKfzDSHfom/D9eRVldLRNOiL5MKjel2JnzZfXYysYQBSzQ==</ds:SignatureValue>
    <ds:KeyInfo>
      <ds:X509Data>
        <ds:X509Certificate>MIIDizCCAnOgAwIBAgIGAZ9xL5RoMA0GCSqGSIb3DQEBCwUAMHcxCzAJBgNVBAYTAkZSMQwwCgYDVQQIEwNJREYxDjAMBgNVBAcTBVBhcmlzMRQwEgYDVQQKEwtTYWJhdGhlIExhYjEbMBkGA1UECxMSSUFNIEZlZGVyYXRpb24gTGFiMRcwFQYDVQQDEw5odWIuc2FiYXRoZS5ldTAeFw0yNjA3MTcxNzQ2MTFaFw0zNjA3MTQxNzQ2MTFaMHcxCzAJBgNVBAYTAkZSMQwwCgYDVQQIEwNJREYxDjAMBgNVBAcTBVBhcmlzMRQwEgYDVQQKEwtTYWJhdGhlIExhYjEbMBkGA1UECxMSSUFNIEZlZGVyYXRpb24gTGFiMRcwFQYDVQQDEw5odWIuc2FiYXRoZS5ldTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKkzQFXYAjWGfkZqnUBgyNVib44sARZYz2M0yH3wXtSLybHKjWkWjo0SzRg4pX9TUrEP29LOeiQTzEukFAoIHWYRdlmQ/mAJopEljUjWXJeflNuF3nBWA/esv3w2ugdztkVSUvA++pGQZYcZ4eQxQjodOaD3BQIHmZXDrezo0Yuw/GcuPXO+knjxF6/vAAwJ2G04TXt5kFlfIWPOXcEZaSACBXrZrb2C550DG4H73jKLCMORFCion2R31VTKwegM8/iCPqmJTPp11PYyrR2hrlgU5AGAPBxWUVimTcb15zNbyUvzUeQYM0/+K9An6EWkhU6VUYT1Qf6Joqx0SG6mFQsCAwEAAaMdMBswGQYDVR0RBBIwEIIOaHViLnNhYmF0aGUuZXUwDQYJKoZIhvcNAQELBQADggEBABsZ7FpVwEzO8VFu2Kzi1kbpIZm6WCgqPgBYf0djQRxgHn02kIGmk/kdfnp3jeX/0MLXbv0SnoJ3hkc4nWQzUVycTd6osxpm69JFQ03mMk7mnzSz79TCpK42g6WCqDyoWQ0h1wIfLOVO0CFtRO+trI2UfN8cQF8Dw49ZtKkBA6kfmrXlBCyAbcktQ87OCoDk3ErC+PaFFfAqUTwywFwGtsXG1mSBI/OTrW8Ul+JnZwF4Cs8d+gfIy7Ehkp6lWWTqikMIocidVjrqPdZXSQlAXhN/sVSngdvxjSJ6sbn2JQx4k2lTypauwlsqsHkJ7AUpKUi+1TQZOH4xhaiqV7lglfk=</ds:X509Certificate>
      </ds:X509Data>
    </ds:KeyInfo>
  </ds:Signature>
  <samlp:Status>
    <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
  </samlp:Status>
  <saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="EPiJS.ZajyIYxSbKro.ZRC5FsZf" IssueInstant="2026-07-20T15:46:43.384Z" Version="2.0">
    <saml:Issuer>https://hub.sabathe.eu</saml:Issuer>
    <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
      <ds:SignedInfo>
        <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
        <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
        <ds:Reference URI="#EPiJS.ZajyIYxSbKro.ZRC5FsZf">
          <ds:Transforms>
            <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
            <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
          </ds:Transforms>
          <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
          <ds:DigestValue>tCvoBw2VO/O9vUXe6E+v+mCEeU9Fz1ID2LzlaQG5Vg4=</ds:DigestValue>
        </ds:Reference>
      </ds:SignedInfo>
      <ds:SignatureValue>M3wyb5WKY6Dl3EhobvLP0Vg48nqjtXLHPs30yerwUo65HRV4+HpilJgNqu8PjB4zz/rCWqZ6MPq02UgB/oEikR5xRlEkeqzVCG0setpkdT2PyJqC/ajQ4f9UqK2wNOs+lg1z3vNurXSHSOQ5Tp1isO9F9R/+7U4mZurJplukzMhbRIcT/PM24wzwp3ay4bf96KlzAzapo4/jkoT5qYJ2q5c46koov6/2N5XsWG6zIt4hOHCJ7lij8t//LrDRy8jTnY+bQ8GRmx9hK3Q6Tg+AEe6AXMKZ6M9p4j7QX2Cws+slxQG0frtM9mOUPmZUBlzMFvHiZdRs1UG+09G0JpH8/A==</ds:SignatureValue>
      <ds:KeyInfo>
        <ds:X509Data>
          <ds:X509Certificate>MIIDizCCAnOgAwIBAgIGAZ9xL5RoMA0GCSqGSIb3DQEBCwUAMHcxCzAJBgNVBAYTAkZSMQwwCgYDVQQIEwNJREYxDjAMBgNVBAcTBVBhcmlzMRQwEgYDVQQKEwtTYWJhdGhlIExhYjEbMBkGA1UECxMSSUFNIEZlZGVyYXRpb24gTGFiMRcwFQYDVQQDEw5odWIuc2FiYXRoZS5ldTAeFw0yNjA3MTcxNzQ2MTFaFw0zNjA3MTQxNzQ2MTFaMHcxCzAJBgNVBAYTAkZSMQwwCgYDVQQIEwNJREYxDjAMBgNVBAcTBVBhcmlzMRQwEgYDVQQKEwtTYWJhdGhlIExhYjEbMBkGA1UECxMSSUFNIEZlZGVyYXRpb24gTGFiMRcwFQYDVQQDEw5odWIuc2FiYXRoZS5ldTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKkzQFXYAjWGfkZqnUBgyNVib44sARZYz2M0yH3wXtSLybHKjWkWjo0SzRg4pX9TUrEP29LOeiQTzEukFAoIHWYRdlmQ/mAJopEljUjWXJeflNuF3nBWA/esv3w2ugdztkVSUvA++pGQZYcZ4eQxQjodOaD3BQIHmZXDrezo0Yuw/GcuPXO+knjxF6/vAAwJ2G04TXt5kFlfIWPOXcEZaSACBXrZrb2C550DG4H73jKLCMORFCion2R31VTKwegM8/iCPqmJTPp11PYyrR2hrlgU5AGAPBxWUVimTcb15zNbyUvzUeQYM0/+K9An6EWkhU6VUYT1Qf6Joqx0SG6mFQsCAwEAAaMdMBswGQYDVR0RBBIwEIIOaHViLnNhYmF0aGUuZXUwDQYJKoZIhvcNAQELBQADggEBABsZ7FpVwEzO8VFu2Kzi1kbpIZm6WCgqPgBYf0djQRxgHn02kIGmk/kdfnp3jeX/0MLXbv0SnoJ3hkc4nWQzUVycTd6osxpm69JFQ03mMk7mnzSz79TCpK42g6WCqDyoWQ0h1wIfLOVO0CFtRO+trI2UfN8cQF8Dw49ZtKkBA6kfmrXlBCyAbcktQ87OCoDk3ErC+PaFFfAqUTwywFwGtsXG1mSBI/OTrW8Ul+JnZwF4Cs8d+gfIy7Ehkp6lWWTqikMIocidVjrqPdZXSQlAXhN/sVSngdvxjSJ6sbn2JQx4k2lTypauwlsqsHkJ7AUpKUi+1TQZOH4xhaiqV7lglfk=</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </ds:Signature>
    <saml:Subject>
      <saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">user1</saml:NameID>
      <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
        <saml:SubjectConfirmationData Recipient="https://saml-a.sabathe.eu/saml/acs" NotOnOrAfter="2026-07-20T15:51:43.384Z" InResponseTo="_C0_9sZYXPU2PFeUPTU5yqY-eFEGmia68"/>
      </saml:SubjectConfirmation>
    </saml:Subject>
    <saml:Conditions NotBefore="2026-07-20T15:41:43.384Z" NotOnOrAfter="2026-07-20T15:51:43.384Z">
      <saml:AudienceRestriction>
        <saml:Audience>https://saml-a.sabathe.eu/metadata</saml:Audience>
      </saml:AudienceRestriction>
    </saml:Conditions>
    <saml:AuthnStatement SessionIndex="EPiJS.ZajyIYxSbKro.ZRC5FsZf" AuthnInstant="2026-07-20T15:35:11.277Z">
      <saml:AuthnContext>
        <saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml:AuthnContextClassRef>
        <saml:AuthenticatingAuthority>https://idp.sabathe.eu/idp/hub2idp/no-mfa</saml:AuthenticatingAuthority>
      </saml:AuthnContext>
    </saml:AuthnStatement>
    <saml:AttributeStatement>
      <saml:Attribute Name="acr" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">urn:sabathe:iamlab:acr:no-mfa</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute Name="authn_profile" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">no-mfa</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute Name="source_idp" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">idp.sabathe.eu</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute Name="amr" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">pwd</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute Name="authn_context" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute Name="email" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">user1@example.test</saml:AttributeValue>
      </saml:Attribute>
    </saml:AttributeStatement>
  </saml:Assertion>
</samlp:Response>
RECEIVED
sp_app · saml-a
SAML_AUTHN_REQUEST_CREATEDsaml-a -> hub
AuthnRequest
Message
AuthnRequest
ID
_C0_9sZYXPU2PFeUPTU5yqY-eFEGmia68
Destination
https://hub.sabathe.eu/idp/SSO.saml2
IssueInstant
2026-07-20T15:46:41Z
Version
2.0
Issuer
https://saml-a.sabathe.eu/metadata
<?xml version="1.0" ?>
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="_C0_9sZYXPU2PFeUPTU5yqY-eFEGmia68" Version="2.0" IssueInstant="2026-07-20T15:46:41Z" Destination="https://hub.sabathe.eu/idp/SSO.saml2" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" AssertionConsumerServiceURL="https://saml-a.sabathe.eu/saml/acs">
  <saml:Issuer>https://saml-a.sabathe.eu/metadata</saml:Issuer>
  <samlp:NameIDPolicy Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" AllowCreate="true"/>
</samlp:AuthnRequest>
SUCCESS
sp_app · saml-a
SAML_RESPONSE_RECEIVEDhub -> saml-a
Response
Message
Response
ID
oQS0VDP1YXbSIehlOtygYh.yzJW
InResponseTo
_C0_9sZYXPU2PFeUPTU5yqY-eFEGmia68
Destination
https://saml-a.sabathe.eu/saml/acs
IssueInstant
2026-07-20T15:46:43.381Z
Version
2.0
Issuer
https://hub.sabathe.eu
StatusCode
urn:oasis:names:tc:SAML:2.0:status:Success
Assertion ID
EPiJS.ZajyIYxSbKro.ZRC5FsZf
NameID
user1
SessionIndex
EPiJS.ZajyIYxSbKro.ZRC5FsZf
Audience
https://saml-a.sabathe.eu/metadata
<?xml version="1.0" ?>
<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" Version="2.0" ID="oQS0VDP1YXbSIehlOtygYh.yzJW" IssueInstant="2026-07-20T15:46:43.381Z" InResponseTo="_C0_9sZYXPU2PFeUPTU5yqY-eFEGmia68" Destination="https://saml-a.sabathe.eu/saml/acs">
  <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">https://hub.sabathe.eu</saml:Issuer>
  <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
    <ds:SignedInfo>
      <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
      <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
      <ds:Reference URI="#oQS0VDP1YXbSIehlOtygYh.yzJW">
        <ds:Transforms>
          <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
          <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
        </ds:Transforms>
        <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
        <ds:DigestValue>Q0VYKSJDxI9gWNWHK3Gy6xsvQiO/TS0nchZLcmVf1fE=</ds:DigestValue>
      </ds:Reference>
    </ds:SignedInfo>
    <ds:SignatureValue>TLbwTNDMaPp/85EG96GmNa6f8fUwuq42QlESAP8VV8b1OBKqYUw/Ce16qgg4JIptJ0EQPGDzwMLVVZaiuzS+e2mJXjfkchbOb7ABrokGT5mGcKE6X8K/7PQ2LJ7bYjzIilaS+lsw6DwrMeXiV6+CJf2z35unHvBxzlZsSEK25Cb7zwQKU22CR0WdKJk4Pm9Q91ytn/yh6AYWYDEfKZBrPHVYuop7cpywMb4mUnvEL1oPF4Z/iIJPIzKEgDkdtu1V49OH6OHxFmd+u4dyhV64FrwEszisHv+1PD6YhMwJuKfzDSHfom/D9eRVldLRNOiL5MKjel2JnzZfXYysYQBSzQ==</ds:SignatureValue>
    <ds:KeyInfo>
      <ds:X509Data>
        <ds:X509Certificate>MIIDizCCAnOgAwIBAgIGAZ9xL5RoMA0GCSqGSIb3DQEBCwUAMHcxCzAJBgNVBAYTAkZSMQwwCgYDVQQIEwNJREYxDjAMBgNVBAcTBVBhcmlzMRQwEgYDVQQKEwtTYWJhdGhlIExhYjEbMBkGA1UECxMSSUFNIEZlZGVyYXRpb24gTGFiMRcwFQYDVQQDEw5odWIuc2FiYXRoZS5ldTAeFw0yNjA3MTcxNzQ2MTFaFw0zNjA3MTQxNzQ2MTFaMHcxCzAJBgNVBAYTAkZSMQwwCgYDVQQIEwNJREYxDjAMBgNVBAcTBVBhcmlzMRQwEgYDVQQKEwtTYWJhdGhlIExhYjEbMBkGA1UECxMSSUFNIEZlZGVyYXRpb24gTGFiMRcwFQYDVQQDEw5odWIuc2FiYXRoZS5ldTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKkzQFXYAjWGfkZqnUBgyNVib44sARZYz2M0yH3wXtSLybHKjWkWjo0SzRg4pX9TUrEP29LOeiQTzEukFAoIHWYRdlmQ/mAJopEljUjWXJeflNuF3nBWA/esv3w2ugdztkVSUvA++pGQZYcZ4eQxQjodOaD3BQIHmZXDrezo0Yuw/GcuPXO+knjxF6/vAAwJ2G04TXt5kFlfIWPOXcEZaSACBXrZrb2C550DG4H73jKLCMORFCion2R31VTKwegM8/iCPqmJTPp11PYyrR2hrlgU5AGAPBxWUVimTcb15zNbyUvzUeQYM0/+K9An6EWkhU6VUYT1Qf6Joqx0SG6mFQsCAwEAAaMdMBswGQYDVR0RBBIwEIIOaHViLnNhYmF0aGUuZXUwDQYJKoZIhvcNAQELBQADggEBABsZ7FpVwEzO8VFu2Kzi1kbpIZm6WCgqPgBYf0djQRxgHn02kIGmk/kdfnp3jeX/0MLXbv0SnoJ3hkc4nWQzUVycTd6osxpm69JFQ03mMk7mnzSz79TCpK42g6WCqDyoWQ0h1wIfLOVO0CFtRO+trI2UfN8cQF8Dw49ZtKkBA6kfmrXlBCyAbcktQ87OCoDk3ErC+PaFFfAqUTwywFwGtsXG1mSBI/OTrW8Ul+JnZwF4Cs8d+gfIy7Ehkp6lWWTqikMIocidVjrqPdZXSQlAXhN/sVSngdvxjSJ6sbn2JQx4k2lTypauwlsqsHkJ7AUpKUi+1TQZOH4xhaiqV7lglfk=</ds:X509Certificate>
      </ds:X509Data>
    </ds:KeyInfo>
  </ds:Signature>
  <samlp:Status>
    <samlp:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>
  </samlp:Status>
  <saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="EPiJS.ZajyIYxSbKro.ZRC5FsZf" IssueInstant="2026-07-20T15:46:43.384Z" Version="2.0">
    <saml:Issuer>https://hub.sabathe.eu</saml:Issuer>
    <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
      <ds:SignedInfo>
        <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
        <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
        <ds:Reference URI="#EPiJS.ZajyIYxSbKro.ZRC5FsZf">
          <ds:Transforms>
            <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
            <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
          </ds:Transforms>
          <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
          <ds:DigestValue>tCvoBw2VO/O9vUXe6E+v+mCEeU9Fz1ID2LzlaQG5Vg4=</ds:DigestValue>
        </ds:Reference>
      </ds:SignedInfo>
      <ds:SignatureValue>M3wyb5WKY6Dl3EhobvLP0Vg48nqjtXLHPs30yerwUo65HRV4+HpilJgNqu8PjB4zz/rCWqZ6MPq02UgB/oEikR5xRlEkeqzVCG0setpkdT2PyJqC/ajQ4f9UqK2wNOs+lg1z3vNurXSHSOQ5Tp1isO9F9R/+7U4mZurJplukzMhbRIcT/PM24wzwp3ay4bf96KlzAzapo4/jkoT5qYJ2q5c46koov6/2N5XsWG6zIt4hOHCJ7lij8t//LrDRy8jTnY+bQ8GRmx9hK3Q6Tg+AEe6AXMKZ6M9p4j7QX2Cws+slxQG0frtM9mOUPmZUBlzMFvHiZdRs1UG+09G0JpH8/A==</ds:SignatureValue>
      <ds:KeyInfo>
        <ds:X509Data>
          <ds:X509Certificate>MIIDizCCAnOgAwIBAgIGAZ9xL5RoMA0GCSqGSIb3DQEBCwUAMHcxCzAJBgNVBAYTAkZSMQwwCgYDVQQIEwNJREYxDjAMBgNVBAcTBVBhcmlzMRQwEgYDVQQKEwtTYWJhdGhlIExhYjEbMBkGA1UECxMSSUFNIEZlZGVyYXRpb24gTGFiMRcwFQYDVQQDEw5odWIuc2FiYXRoZS5ldTAeFw0yNjA3MTcxNzQ2MTFaFw0zNjA3MTQxNzQ2MTFaMHcxCzAJBgNVBAYTAkZSMQwwCgYDVQQIEwNJREYxDjAMBgNVBAcTBVBhcmlzMRQwEgYDVQQKEwtTYWJhdGhlIExhYjEbMBkGA1UECxMSSUFNIEZlZGVyYXRpb24gTGFiMRcwFQYDVQQDEw5odWIuc2FiYXRoZS5ldTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKkzQFXYAjWGfkZqnUBgyNVib44sARZYz2M0yH3wXtSLybHKjWkWjo0SzRg4pX9TUrEP29LOeiQTzEukFAoIHWYRdlmQ/mAJopEljUjWXJeflNuF3nBWA/esv3w2ugdztkVSUvA++pGQZYcZ4eQxQjodOaD3BQIHmZXDrezo0Yuw/GcuPXO+knjxF6/vAAwJ2G04TXt5kFlfIWPOXcEZaSACBXrZrb2C550DG4H73jKLCMORFCion2R31VTKwegM8/iCPqmJTPp11PYyrR2hrlgU5AGAPBxWUVimTcb15zNbyUvzUeQYM0/+K9An6EWkhU6VUYT1Qf6Joqx0SG6mFQsCAwEAAaMdMBswGQYDVR0RBBIwEIIOaHViLnNhYmF0aGUuZXUwDQYJKoZIhvcNAQELBQADggEBABsZ7FpVwEzO8VFu2Kzi1kbpIZm6WCgqPgBYf0djQRxgHn02kIGmk/kdfnp3jeX/0MLXbv0SnoJ3hkc4nWQzUVycTd6osxpm69JFQ03mMk7mnzSz79TCpK42g6WCqDyoWQ0h1wIfLOVO0CFtRO+trI2UfN8cQF8Dw49ZtKkBA6kfmrXlBCyAbcktQ87OCoDk3ErC+PaFFfAqUTwywFwGtsXG1mSBI/OTrW8Ul+JnZwF4Cs8d+gfIy7Ehkp6lWWTqikMIocidVjrqPdZXSQlAXhN/sVSngdvxjSJ6sbn2JQx4k2lTypauwlsqsHkJ7AUpKUi+1TQZOH4xhaiqV7lglfk=</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </ds:Signature>
    <saml:Subject>
      <saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">user1</saml:NameID>
      <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
        <saml:SubjectConfirmationData Recipient="https://saml-a.sabathe.eu/saml/acs" NotOnOrAfter="2026-07-20T15:51:43.384Z" InResponseTo="_C0_9sZYXPU2PFeUPTU5yqY-eFEGmia68"/>
      </saml:SubjectConfirmation>
    </saml:Subject>
    <saml:Conditions NotBefore="2026-07-20T15:41:43.384Z" NotOnOrAfter="2026-07-20T15:51:43.384Z">
      <saml:AudienceRestriction>
        <saml:Audience>https://saml-a.sabathe.eu/metadata</saml:Audience>
      </saml:AudienceRestriction>
    </saml:Conditions>
    <saml:AuthnStatement SessionIndex="EPiJS.ZajyIYxSbKro.ZRC5FsZf" AuthnInstant="2026-07-20T15:35:11.277Z">
      <saml:AuthnContext>
        <saml:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified</saml:AuthnContextClassRef>
        <saml:AuthenticatingAuthority>https://idp.sabathe.eu/idp/hub2idp/no-mfa</saml:AuthenticatingAuthority>
      </saml:AuthnContext>
    </saml:AuthnStatement>
    <saml:AttributeStatement>
      <saml:Attribute Name="acr" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">urn:sabathe:iamlab:acr:no-mfa</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute Name="authn_profile" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">no-mfa</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute Name="source_idp" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">idp.sabathe.eu</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute Name="amr" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">pwd</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute Name="authn_context" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AttributeValue>
      </saml:Attribute>
      <saml:Attribute Name="email" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
        <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string">user1@example.test</saml:AttributeValue>
      </saml:Attribute>
    </saml:AttributeStatement>
  </saml:Assertion>
</samlp:Response>
RECEIVED
Data refreshed from IAM-Lab runtimeStreaming liveAuto refreshManual