Infamous SAML 2 SSO profile is not configured Error

Ken Hammer khammer at umich.edu
Thu Jun 14 19:53:03 BST 2012


  Greetings,

  I understand that this error could indicate a problem with the SP 
metadata. I have verified that the EntityIDs match in both metadata 
files from the SP and what is in the InCommon metadata file.
What I wish to know is, could the following line be considered different 
to my IdP causing the SAML 2 SSO profile error?
The Location for AssertionConsumerService  in the metadata taken 
directly from the SP is different from the one that is listed in 
InCommon's metadata.

 From SP metadata: 
Location="https://sp-name.domain.edu/Shibboleth.sso/SAML2/POST" index="1"/>
 From InCommon 
Location="https://sp-different.domain.edu/sp/Shibboleth.sso/SAML2/POST" 
index="1"/>

Metadata sent from SP

<md:AssertionConsumerService
       Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location="https://sp-name.domain.edu/Shibboleth.sso/SAML2/POST" index="1"/>


Metadata for SP in InCommon metadata file:

<md:AssertionConsumerService 
xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
      Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location="https://sp-different.domain.edu/sp/Shibboleth.sso/SAML2/POST" 
index="1"/>

Would this difference cause the error?

Thank-you for taking the time to look at this email.



-- 
Ken Hammer




More information about the users mailing list