2018-08-14 09:23:09,480 INFO [PolicyBasedAuthenticationManager] - <Authenticated principal [klintduotest] with attributes [{displayName=[klintduotest], GOBTPAC_EXTERNAL_USER=[klintduotest], memberOf=[CN=auth_duoOU=groups,DC=example,DC=com], msDS-UserPasswordExpiryTimeComputed=[132094270306397245], pwdLastSet=[131778046306397245], sAMAccountName=[klintduotest]}] via credentials [[klintduotest]].>2018-08-14 09:23:09,481 INFO [Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN=============================================================WHO: klintduotestWHAT: Supplied credentials: [klintduotest]ACTION: AUTHENTICATION_SUCCESSAPPLICATION: CASWHEN: Tue Aug 14 09:23:09 MDT 2018CLIENT IP ADDRESS: 192.168.1.176SERVER IP ADDRESS: 192.168.1.25=============================================================
>2018-08-14 09:23:09,786 INFO [Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN=============================================================WHO: klintduotestWHAT: [event=mfa-duo,timestamp=Tue Aug 14 09:23:09 MDT 2018,source=RegisteredServicePrincipalAttributeMultifactorAuthenticationPolicyEventResolver]ACTION: AUTHENTICATION_EVENT_TRIGGEREDAPPLICATION: CASWHEN: Tue Aug 14 09:23:09 MDT 2018CLIENT IP ADDRESS: 192.168.1.176SERVER IP ADDRESS: 192.168.1.25=============================================================
>2018-08-14 09:23:10,198 INFO [Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN=============================================================WHO: klintduotestWHAT: TGT-1-*********************************************************H4tIURR-L4-te-casdev1ACTION: TICKET_GRANTING_TICKET_CREATEDAPPLICATION: CASWHEN: Tue Aug 14 09:23:10 MDT 2018CLIENT IP ADDRESS: 192.168.1.176SERVER IP ADDRESS: 192.168.1.25=============================================================
>2018-08-14 09:23:10,255 INFO [DefaultCentralAuthenticationService] - <Granted ticket [ST-1-Fetae-ngqx0SA86AFbVFmdkssFM-te-casdev1] for service [https://hadoopdev1.weber.edu/casdev1/] and principal [klintduotest]>2018-08-14 09:23:10,256 INFO [Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN=============================================================WHO: klintduotestWHAT: ST-1-Fetae-ngqx0SA86AFbVFmdkssFM-te-casdev1 for https://hadoopdev1.weber.edu/casdev1/ACTION: SERVICE_TICKET_CREATEDAPPLICATION: CASWHEN: Tue Aug 14 09:23:10 MDT 2018CLIENT IP ADDRESS: 192.168.1.176SERVER IP ADDRESS: 192.168.1.25=============================================================
>2018-08-14 09:23:10,382 INFO [Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN=============================================================WHO: klintduotestWHAT: ST-1-Fetae-ngqx0SA86AFbVFmdkssFM-te-casdev1ACTION: SERVICE_TICKET_VALIDATEDAPPLICATION: CASWHEN: Tue Aug 14 09:23:10 MDT 2018CLIENT IP ADDRESS: 192.168.1.35SERVER IP ADDRESS: 192.168.1.25=============================================================
>2018-08-14 09:23:10,393 WARN [DefaultAuthenticationContextValidator] - <No satisfied multifactor authentication providers are recorded in the current authentication context.> <cas:authenticationFailure code="INVALID_AUTHENTICATION_CONTEXT">The validation request for ['ST-1-Fetae-ngqx0SA86AFbVFmdkssFM-te-casdev1'] cannot be satisfied. The request is either unrecognized or unfulfilled.</cas:authenticationFailure></cas:serviceResponse>2018-08-15 09:12:38,663 DEBUG [BaseDuoSecurityAuthenticationService] - <Contacting Duo to inquire about username [klintduotest]>2018-08-15 09:12:38,921 DEBUG [BaseDuoSecurityAuthenticationService] - <Received Duo admin response [{"response": {"result": "allow", "status_msg": "Logging you in automatically..."}, "stat": "OK"}]>2018-08-15 09:12:38,921 DEBUG [DefaultDuoMultifactorAuthenticationProvider] - <Found duo user account status [org.apereo.cas.adaptors.duo.DuoUserAccount@49754dc2[status=ALLOW,enrollPortalUrl=<null>]] for [klintduotest]>2018-08-15 09:12:38,921 DEBUG [DefaultDuoMultifactorAuthenticationProvider] - <Account status is set for allow/bypass for [klintduotest]>2018-08-15 09:13:27,126 DEBUG [BaseDuoSecurityAuthenticationService] - <Contacting Duo to inquire about username [klintholmes]>2018-08-15 09:13:27,222 DEBUG [BaseDuoSecurityAuthenticationService] - <Received Duo admin response [{"response": {"devices": REMOVED}>2018-08-15 09:13:27,222 DEBUG [DefaultDuoMultifactorAuthenticationProvider] - <Found duo user account status [org.apereo.cas.adaptors.duo.DuoUserAccount@a0af2d9[status=AUTH,enrollPortalUrl=<null>]] for [klintholmes]>2018-08-15 09:13:27,222 DEBUG [BaseDuoSecurityAuthenticationService] - <Contacting Duo to inquire about username [klintholmes]>2018-08-15 09:13:27,335 DEBUG [BaseDuoSecurityAuthenticationService] - <Received Duo admin response [{"response": {"devices": REMOVED}>2018-08-15 09:13:27,335 DEBUG [DefaultDuoMultifactorAuthenticationProvider] - <Found duo user account status [org.apereo.cas.adaptors.duo.DuoUserAccount@5e565608[status=AUTH,enrollPortalUrl=<null>]] for [klintholmes]>2018-08-15 09:13:27,336 DEBUG [BaseDuoSecurityAuthenticationService] - <Contacting Duo to inquire about username [klintholmes]>2018-08-15 09:13:27,424 DEBUG [BaseDuoSecurityAuthenticationService] - <Received Duo admin response [{"response": {"devices": REMOVED}>2018-08-15 09:13:39,281 DEBUG [BasicDuoSecurityAuthenticationService] - <Calling DuoWeb.verifyResponse with signed request token '[AUTH|REMOVED|REMOVED|REMOVED|REMOVED'>2018-08-15 09:13:39,281 DEBUG [DuoAuthenticationHandler] - <Response from Duo verify: [klintholmes]>2018-08-15 09:13:39,281 INFO [DuoAuthenticationHandler] - <Successful Duo authentication for [klintholmes]>2018-08-15 09:13:39,281 INFO [PolicyBasedAuthenticationManager] - <Authenticated principal [klintholmes] with attributes [{}] via credentials [[[username=klintholmes,signedDuoResponse=AUTH|REMOVED|REMOVED|REMOVED|REMOVED]]].>.......2018-08-15 15:19:14,052 DEBUG [DefaultAuthenticationContextValidator] - <Attempting to match requested authentication context [mfa-duo] against [[]]>2018-08-15 15:19:14,052 DEBUG [DefaultAuthenticationContextValidator] - <No authentication context could be determined based on authentication attribute [authnContextClass]>2018-08-15 15:19:14,052 WARN [DefaultAuthenticationContextValidator] - <No satisfied multifactor authentication providers are recorded in the current authentication context.>2018-08-15 15:19:16,572 DEBUG [WebApplicationServiceFactory] - <No service is specified in the request. Skipping service creation>...
if (acct.getStatus() == DuoUserAccountAuthStatus.ALLOW) { LOGGER.debug("Account status is set for allow/bypass for [{}]", principal); return false; }
...