unable to locate metadata for identity provider
Pavan K
pavanonnet1986 at gmail.com
Wed Aug 31 18:29:52 BST 2011
Thank you Nate. I fixed the configruation issue by removing the Metada
filter in "shibboleth2.xml". As you said, I am running into other issues
after fixing that error. I am looking into that. Thank you very much for
your help.
-Pavan
On Tue, Aug 30, 2011 at 4:34 PM, Nate Klingenstein <ndk at internet2.edu>wrote:
> Pavan,
>
> You're making good progress on a somewhat customized installation. There
> are a couple mis-steps, though.
>
> My identity provider "entityId" is : *http://
> <machineA>:8080/idp/shibboleth* and the metadata is accesible by using
> that URL.
>
>
> Putting a port in an entityID is not usually recommended, but you can do
> it. Also, metadata should be signed if it's hosted over http -- but this is
> fine for a test deployment.
>
> After installing the Service provider, I modified "shibboleth2.xml" with
> the following changes,
>
> Modified service provider "entityId" to *"http://<machineB>/sp/shibboleth"
> * in "<ApplicationDefaults" xml tag.
>
> Added SSO:
>
> *<SSO entityID="http://<machineA>:8080/idp/shibboleth">
> SAML2 SAML1
> </SSO>
> *
>
>
> This is all fine.
>
> Added metadata provider:
>
> * <MetadataProvider type="Chaining">
> <MetadataProvider type="XML" uri="http://
> <machineA>:8080/idp/shibboleth"
> backingFilePath="federation-metadata.xml"
> reloadInterval="7200">
> <MetadataFilter type="RequireValidUntil"
> maxValidityInterval="2419200"/>
> </MetadataProvider>
> </MetadataProvider>
> *
>
>
> This should be okay, too.
>
> And i modified identity provider "relying-party.xml" file with the
> following changes,
>
> * <rp:AnonymousRelyingParty provider="http://<machineB>/sp/shibboleth"
> defaultSigningCredentialRef="IdPCredential"/>
>
> <rp:DefaultRelyingParty provider="http://<machineB>/sp/shibboleth"
> defaultSigningCredentialRef="IdPCredential">*
>
>
> This is not correct. The provider attribute in these elements in
> relying-party.xml refers to the entityID that the IdP will use to name
> itself when it is talking to relying parties. This should be http://<machineA>:8080/idp/shibboleth,
> which should match the original values.
>
> These properties were really hard to name right, and obviously, the current
> names confused you.
>
> After these changes i have restarted identity provider, services provider
> and apache services. I am trying to hit the url; *"http://
> <machineB>/Shibboleth.sso/Login"*
>
>
> I am getting the following error:
>
> *opensaml::saml2md::MetadataException at (http://
> <machineB>/Shibboleth.sso/Login)*
>
> *Unable to locate metadata for identity provider (http://
> <machineA>:8080/idp/shibboleth)*
>
>
> Either the metadata for the identity provider isn't being loaded correctly,
> or the entityID in the metadata file doesn't match http://<machineA>:8080/idp/shibboleth.
> There needs to be an entityID in metadata loaded by the SP that precisely
> matches the IdP's configured entityID, and the entityID in the SSO element
> has to be a string match of that entityID too. You can check shibd.log
> during startup and login attempt to determine where the mismatch is.
>
> That will fix this problem. You may encounter other problems after you
> resolve this one.
>
> Take care,
> Nate.
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20110831/53b30632/attachment.html
More information about the users
mailing list