<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style id="owaParaStyle">P {
        MARGIN-TOP: 0px; MARGIN-BOTTOM: 0px
}
</style>
</head>
<body fPStyle="1" ocsi="0">
<div style="direction: ltr;font-family: Tahoma;color: #000000;font-size: 10pt;">
<p>This is not the right list for your question.&nbsp; You may want to try <a href="mailto:users@shibboleth.net">
users@shibboleth.net</a>, as the audience of that list is much broader and would likely have more experience with ADFS and the specific problem you are having.</p>
<p>&nbsp;</p>
<p>From what you posted here it sounds like a problem on the ADFS side though, it may be with the specific configuration of the Shibboleth IdP, but it's an ADFS configuration issue (the warnings you listed below sound like a simple issue of SAML 2 Metadata
 that may need to be trimmed down to just SAML 2.0 bindings/profiles).&nbsp; And the exception details sound like a firewall or permissions issue.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div style="FONT-FAMILY: Times New Roman; COLOR: #000000; FONT-SIZE: 16px">
<hr tabindex="-1">
<div style="DIRECTION: ltr" id="divRpF43288"><font color="#000000" size="2" face="Tahoma"><b>From:</b> dev-bounces@shibboleth.net [dev-bounces@shibboleth.net] on behalf of giuseppe parisella [gparise2la@gmail.com]<br>
<b>Sent:</b> Friday, January 06, 2012 12:25 PM<br>
<b>To:</b> dev@shibboleth.net<br>
<b>Subject:</b> ADFS communication problem<br>
</font><br>
</div>
<div></div>
<div>Hi,<br>
sorry for my english. I'm following the guide <strong>Federated Collaboration with Shibboleth 2.0 and SharePoint 2010 Technologies</strong> at the site
<a href="http://technet.microsoft.com/en-us/library/adfs2-step-by-step-guides%28WS.10%29.aspx" target="_blank">
http://technet.microsoft.com/en-us/library/adfs2-step-by-step-guides%28WS.10%29.aspx</a>. So I have 3 virtual machines (one for ADFS, one for Shibboleth and one for Sharepoint2010). I have configured the shibboleth machine as showed in the guide and the status
 is ok (the <a href="https://idmgt-ip0.idmgtext.demo:8443/idp/profile/Status" target="_blank">
https://idmgt-ip0.idmgtext.demo:8443/idp/profile/Status</a> page shows ok). For the ADFS side, the guide doesn't tell anything and so I have followed other documents on the web. Before configure the Sharepoint side, I have to test if it's all right and so,
 from the ADFS machine, I visit <a href="https://sts.idmgt.demo/adfs/ls/IdpInitiatedSignon.aspx" target="_blank">
https://sts.idmgt.demo/adfs/ls/IdpInitiatedSignon.aspx</a> (sts.idmgt.demo is the ADFS machine'd alias name) from Internet Explorer and gets out the following error message:
<br>
<p style="LINE-HEIGHT: normal; MARGIN: 5pt 0in; FONT-FAMILY: arial,helvetica,sans-serif">
<font size="&#43;0"><span>There was a problem accessing the site. Try to browse to the site again.
</span></font></p>
<font style="FONT-FAMILY: arial,helvetica,sans-serif" size="2"></font>
<p style="LINE-HEIGHT: normal; MARGIN: 5pt 0in; FONT-FAMILY: arial,helvetica,sans-serif">
<font size="&#43;0"><span>If the problem persists, contact the administrator of this site and provide the reference number to identify the problem.
<br>
</span></font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 5pt 0in; FONT-FAMILY: times new roman,serif">
<font style="FONT-FAMILY: arial,helvetica,sans-serif" size="2"><span id="ctl00_ContentPlaceHolder1_ExceptionMessageLabel">MSIS7012: An error occurred while processing the request. Contact your administrator for details.</span></font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 5pt 0in; FONT-FAMILY: times new roman,serif">
<br>
<font style="FONT-FAMILY: arial,helvetica,sans-serif" size="2"><span id="ctl00_ContentPlaceHolder1_ExceptionMessageLabel"></span></font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 5pt 0in; FONT-FAMILY: times new roman,serif">
<font style="FONT-FAMILY: arial,helvetica,sans-serif" size="2"><span id="ctl00_ContentPlaceHolder1_ExceptionMessageLabel">In the Event Viewer there is a Warning
<br>
</span></font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 5pt 0in; FONT-FAMILY: times new roman,serif">
<font style="FONT-FAMILY: arial,helvetica,sans-serif" size="2"><span id="ctl00_ContentPlaceHolder1_ExceptionMessageLabel">Trust monitoring service detected changes in policy of 'Shibboleth IdP', but did not automatically apply the changes on the trust partner.
<br>
<br>
Additional Data <br>
Warnings: <br>
MSIS7524: A 'ArtifactResolutionService' endpoint was ignored because its binding 'urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding' is not supported.<br>
MSIS7524: A 'SamlSingleSignOnService' endpoint was ignored because its binding 'urn:mace:shibboleth:1.0:profiles:AuthnRequest' is not supported.<br>
MSIS7524: A 'SamlSingleSignOnService' endpoint was ignored because its binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign' is not supported.</span></font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 5pt 0in; FONT-FAMILY: times new roman,serif">
<br>
<font style="FONT-FAMILY: arial,helvetica,sans-serif" size="2"><span id="ctl00_ContentPlaceHolder1_ExceptionMessageLabel"></span></font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 5pt 0in; FONT-FAMILY: times new roman,serif">
<font style="FONT-FAMILY: arial,helvetica,sans-serif" size="2"><span id="ctl00_ContentPlaceHolder1_ExceptionMessageLabel">and 4 Errors with EventID=364:</span></font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 5pt 0in; FONT-FAMILY: times new roman,serif">
<font style="FONT-FAMILY: arial,helvetica,sans-serif" size="2"><span id="ctl00_ContentPlaceHolder1_ExceptionMessageLabel">Encountered error during federation passive request.
<br>
<br>
Additional Data <br>
<br>
Exception details: <br>
Microsoft.IdentityServer.Configuration.ReadServiceConfigFailedException: MSIS2001: Configuration service URL is not configured. ---&gt; Microsoft.IdentityServer.PolicyModel.Client.StorageAuthorizationException: ADMIN0120: The client is not authorized to access
 the endpoint net.tcp://localhost:1500/policy. The client process must be run with elevated administrative privileges.<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.PolicyModel.Client.PolicyStoreClientManager.SearchWorker(Filter filter, Int32 maxObjects, String[] propertyNames, Boolean firstTry, PropertyFactoryBase propertyFactory)<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.PolicyModel.Client.PolicyStoreClientManager.Search(Filter filter, Int32 maxObjects, String[] propertyNames, PropertyFactoryBase propertyFactory)<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.PolicyModel.Client.PolicyManagerBase.Search[T](Filter filter, Int32 maxItems, String[] properties, PropertyFactoryBase propertyFactory)<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.PolicyModel.Client.PolicyManagerBase.GetItem[T](Filter filter, String[] properties, PropertyFactoryBase propertyFactory)<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.Configuration.ServiceConfigurationReader.ReadServiceConfiguration()<br>
&nbsp;&nbsp; --- End of inner exception stack trace ---<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.Configuration.ServiceConfigurationReader.ReadServiceConfiguration()<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.Configuration.ServiceConfigurationReader.get_ServiceConfiguration()<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.Configuration.ServiceConfigurationReader.GetHostNetTcpPort()<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.Web.PassivePolicyManager..ctor()<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.Web.FederationPassiveAuthentication.GetIssuerFriendlyName()<br>
<br>
Microsoft.IdentityServer.PolicyModel.Client.StorageAuthorizationException: ADMIN0120: The client is not authorized to access the endpoint net.tcp://localhost:1500/policy. The client process must be run with elevated administrative privileges.<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.PolicyModel.Client.PolicyStoreClientManager.SearchWorker(Filter filter, Int32 maxObjects, String[] propertyNames, Boolean firstTry, PropertyFactoryBase propertyFactory)<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.PolicyModel.Client.PolicyStoreClientManager.Search(Filter filter, Int32 maxObjects, String[] propertyNames, PropertyFactoryBase propertyFactory)<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.PolicyModel.Client.PolicyManagerBase.Search[T](Filter filter, Int32 maxItems, String[] properties, PropertyFactoryBase propertyFactory)<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.PolicyModel.Client.PolicyManagerBase.GetItem[T](Filter filter, String[] properties, PropertyFactoryBase propertyFactory)<br>
&nbsp;&nbsp; at Microsoft.IdentityServer.Configuration.ServiceConfigurationReader.ReadServiceConfiguration()<br>
<br>
<br>
The problem is on this machine or I was wrong something in the Shibboleth configuration?</span></font></p>
<p style="LINE-HEIGHT: normal; MARGIN: 5pt 0in; FONT-FAMILY: times new roman,serif">
<font style="FONT-FAMILY: arial,helvetica,sans-serif" size="2"><span id="ctl00_ContentPlaceHolder1_ExceptionMessageLabel">Thanks<br>
</span></font></p>
<h1><span style="FONT-FAMILY: 'Verdana','sans-serif'; FONT-SIZE: 9pt; FONT-WEIGHT: normal"><br>
</span></h1>
</div>
</div>
</div>
</body>
</html>