where is HTTPS/HTTP set for the relying party endpoint return?

Chad La Joie lajoie at itumi.biz
Fri Aug 5 19:15:13 BST 2011


Then apparently you didn't actually update them like you thought.  If
you look at the FAQ for the IdP this is a common issue and it's 99% of
the time its related to metadata.

On Fri, Aug 5, 2011 at 14:13, Peterson, Tommy
<Tommy.Peterson at xpandcorp.com> wrote:
> But I updated all those including the POST one to HTTPS beforehand it I still get the error.
>
> -----Original Message-----
> From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Kevin P. Foote
> Sent: Friday, August 05, 2011 2:12 PM
> To: Shib Users
> Subject: Re: where is HTTPS/HTTP set for the relying party endpoint return?
>
>
> -> What determines whether the return endpoint for the SP on the IDP is HTTPS or HTTP?
>
> METADATA. specifically the SP's metadata that your IdP is currently using
>
> ------
> thanks
>  kevin.foote
>
> On Fri, 5 Aug 2011, Peterson, Tommy wrote:
>
> -> What determines whether the return endpoint for the SP on the IDP is HTTPS or HTTP?
> ->
> -> I updated the URLS in the IDP metadata to HTTPS. The same for relying-party.xml and shibboleth2.xml. But when I did I get the following error in the browser and the IDP log.
> ->
> -> 13:49:18.685 - WARN [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:202] - Relying party 'https://(mydomain)/moodle' requested the response to be returned to endpoint with ACS URL 'http://(mydomain)/Shibboleth.sso/SAML2/POST'  and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however no endpoint, with that URL and using a supported binding,  can be found in the relying party's metadata
> ->
> -> 13:49:18.685 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:424] - No return endpoint available for relying party https://(mydomain)/moodle
> ->
> ->
> -> So when I go into the IDP's metadata and change the Shibboloth.sso/SAML2/POST URL to HTTP from HTTPS all works OK. But I am wondering what specifically dictates whether this is HTTPS or HTTP? Is it a setting in the SP? IDP? And what file and attribute specifically?
> ->
> -> Thanks.
> ->
> -> ________________________________
> -> This message contains Devin Group confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail.
> -> Please notify the sender immediately by e-mail if you have received this e-mail in error and delete this e-mail from your system. E-mail transmissions cannot be guaranteed secure, error-free and information could be intercepted, corrupted, lost, destroyed, arrive late, incomplete, or contain viruses. The sender therefore does not accept liability for errors or omissions in the contents of this message which may arise as result of transmission. If verification is required please request hard-copy version.
> ->
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
> This message contains Devin Group confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail.
>  Please notify the sender immediately by e-mail if you have received this e-mail in error and delete this e-mail from your system. E-mail transmissions cannot be guaranteed secure, error-free and information could be intercepted, corrupted, lost, destroyed, arrive late, incomplete, or contain viruses. The sender therefore does not accept liability for errors or omissions in the contents of this message which may arise as result of transmission. If verification is required please request hard-copy version.
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list