Discovery Service/WAYF v1.2.1 Shibboleth service provider and simpleSAMLphp - cannot recognize federation metadata
Coeus[TM]
coeus.ph at gmail.com
Fri Jun 8 08:53:53 BST 2012
Hi Rod,
I hoped that was (EmailAddress text content) the reason why.
As instructed from the previous post, I have directed the metadata url
to the local path so I can test independently.
e.g.
wayfconfig.xml -> url="file:/shibboleth/feds/birk-idp.xml"
shibboleth2.xml -> uri="birk-idp.xml"
and tried several tests as enumerated below:
T E S T # 3:
- modified birk-idp.xml;
- removed other entities from the federation's metadata and left the
entity for the University of Iceland only
- removed the EmailAddress and PhoneNumber tags to prevent the ERROR
OpenSAML.MetadataProvider.XML : metadata intance failed manual
validation
and included our SP's entity/metadata (copied from another
federation's metadata)
LOGS
discoveryService.log
--------------------
06:01:32.611 - INFO
[org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:423]
- New metadata succesfully loaded for
'/etc/shibboleth/federations/birk-idp.xml'
06:01:32.611 - INFO
[org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:271]
- Next refresh cycle for metadata provider
'/etc/shibboleth/federations/birk-idp.xml' will occur on
'2012-06-08T08:01:32.603Z' ('2012-06-08T09:01:32.603+01:00' local
time)
shibd.log
---------
2012-06-08 06:07:09 INFO OpenSAML.MetadataProvider.XML : loaded XML
resource (/etc/shibboleth/federations/birk-idp.xml)
RESULT
- The discovery page loaded but still did not displayed the federation
name and its Idps.
T E S T # 4
- this time, used another entity and for the Aarhus University only
- EmailAddress and TelephoneNumber tags have values
- still, our SP's entity/metadata is included in the federation metadata
discoveryService.log
--------------------
07:14:26.216 - INFO
[org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:423]
- New metadata succesfully loaded for
'/etc/shibboleth/federations/birk-idp.xml'
07:14:26.216 - INFO
[org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:271]
- Next refresh cycle for metadata provider
'/etc/shibboleth/federations/birk-idp.xml' will occur on
'2012-06-08T09:14:26.212Z' ('2012-06-08T10:14:26.212+01:00' local
time)
jboss log
---------
2012-06-08 07:14:21,809 ERROR
[org.apache.catalina.core.ContainerBase.[jboss.web].[localhost].[/discovery].[WAYF]]
(ajp-192.168.59.24-8009-8) Allocate exception for servlet WAYF
java.lang.NullPointerException
at org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider.refresh(AbstractReloadingMetadataProvider.java:269)
at org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider.doInitialization(AbstractReloadingMetadataProvider.java:236)
at org.opensaml.saml2.metadata.provider.AbstractMetadataProvider.initialize(AbstractMetadataProvider.java:407)
at edu.internet2.middleware.shibboleth.wayf.IdPSiteSet.<init>(IdPSiteSet.java:179)
at edu.internet2.middleware.shibboleth.wayf.WayfService.init(WayfService.java:181)
at javax.servlet.GenericServlet.init(GenericServlet.java:212)
at org.apache.catalina.core.StandardWrapper.loadServlet(StandardWrapper.java:1048)
at org.apache.catalina.core.StandardWrapper.allocate(StandardWrapper.java:777)
at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:129)
at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:191)
at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:190)
at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:92)
at org.jboss.web.tomcat.security.SecurityContextEstablishmentValve.process(SecurityContextEstablishmentValve.java:126)
at org.jboss.web.tomcat.security.SecurityContextEstablishmentValve.invoke(SecurityContextEstablishmentValve.java:70)
at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127)
at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
at org.jboss.web.tomcat.service.jca.CachedConnectionValve.invoke(CachedConnectionValve.java:158)
at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:330)
at org.apache.coyote.ajp.AjpProcessor.process(AjpProcessor.java:436)
at org.apache.coyote.ajp.AjpProtocol$AjpConnectionHandler.process(AjpProtocol.java:384)
at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:447)
at java.lang.Thread.run(Thread.java:662)
RESULT
- The page did not load at all.
T E S T # 5
- used again the entity for the Aarhus University only
- removed EmailAddress and TelephoneNumber tags
- removed our SP's entity/metadata
LOGS
shibd.log
---------
2012-06-08 07:27:16 INFO OpenSAML.MetadataProvider.XML : loaded XML
resource (/etc/shibboleth/federations/birk-idp.xml)
discoveryService.log
--------------------
07:23:44.660 - INFO
[org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:423]
- New metadata succesfully loaded for
'/etc/shibboleth/federations/birk-idp.xml'
07:23:44.661 - INFO
[org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:271]
- Next refresh cycle for metadata provider
'/etc/shibboleth/federations/birk-idp.xml' will occur on
'2012-06-08T09:23:44.655Z' ('2012-06-08T10:23:44.655+01:00' local
time)
RESULT
- Page did load but no signs of the federation and its Idps.
T E S T #6
- modified birk-idp.xml
- copied the *contents* of *another working federation metadata* and
*replaced* the contents of birk-idp.xml
- note: this time, it's the same file but different content
LOGS
No signs of errors. All federation metadata was loaded successfully.
RESULT
- The page was loaded, the Denmark federation and the Idps as
contained in the birk-idp.xml were successfully displayed.
Please allow me to conclude that that type of federation metadata is
not compatible with the discovery page we are using? and having
said that an empty XML element <md:EmailAddress/> was found which is
not allowed to be empty?
I still have not tested using the EDS though but I will and let you
know the result.
Thank you very much.
More information about the users
mailing list