Infamous SAML 2 SSO profile is not configured Error
Ken Hammer
khammer at umich.edu
Thu Jun 14 19:53:03 BST 2012
Greetings,
I understand that this error could indicate a problem with the SP
metadata. I have verified that the EntityIDs match in both metadata
files from the SP and what is in the InCommon metadata file.
What I wish to know is, could the following line be considered different
to my IdP causing the SAML 2 SSO profile error?
The Location for AssertionConsumerService in the metadata taken
directly from the SP is different from the one that is listed in
InCommon's metadata.
From SP metadata:
Location="https://sp-name.domain.edu/Shibboleth.sso/SAML2/POST" index="1"/>
From InCommon
Location="https://sp-different.domain.edu/sp/Shibboleth.sso/SAML2/POST"
index="1"/>
Metadata sent from SP
<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location="https://sp-name.domain.edu/Shibboleth.sso/SAML2/POST" index="1"/>
Metadata for SP in InCommon metadata file:
<md:AssertionConsumerService
xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location="https://sp-different.domain.edu/sp/Shibboleth.sso/SAML2/POST"
index="1"/>
Would this difference cause the error?
Thank-you for taking the time to look at this email.
--
Ken Hammer
More information about the users
mailing list