Wrong metadata in relying party even if it's OK to my eyes...

Per Ejeklint per.ejeklint at heimore.com
Fri May 4 14:10:30 BST 2012


Hey world, new Shibboleth user here!

I'm trying to set up a local installation of IdP and SP on the same machine (Mac OS X Lion) and have gotten it to work - almost. I stumble upon a mismatch in URLs after successfully have logged in with the configured LDAP. IDP says

WARN [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] - Relying party 'https://sp.ejeklint.se/shibboleth' requested the response to be returned to endpoint with ACS URL 'https://www.example.com/Shibboleth.sso/SAML2/POST'  and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however no endpoint, with that URL and using a supported binding,  can be found in the relying party's metadata 

and that's fair enough as "https://www.example.com..." is not a correct URL. But the thing is that I share metadata ONLY through files, and in my metadata file for the SP there is not a trace left of "www.example.com" - my own machine name is there.

For some reason the IdP seem to pick the ACS URL from the running SP and not from the metadata file I have provided. Now I'm stuck and need a (gentle) kick in the right direction.

Here's my metadata tags in RelyingParty.xml:

    <!-- ========================================== -->
    <!--      Metadata Configuration                -->
    <!-- ========================================== -->
    <!-- MetadataProvider the combining other MetadataProviders -->
    <metadata:MetadataProvider id="ShibbolethMetadata" xsi:type="metadata:ChainingMetadataProvider">
    
    	<!-- Load the IdP's own metadata.  This is necessary for artifact support. -->
        <metadata:MetadataProvider id="IdPMD" xsi:type="metadata:ResourceBackedMetadataProvider">
            <metadata:MetadataResource xsi:type="resource:FilesystemResource" file="/opt/shibboleth-idp/metadata/idp-metadata.xml"/>
        </metadata:MetadataProvider>
        
        <!-- Load the SP's metadata.  -->
        <metadata:MetadataProvider xsi:type="FilesystemMetadataProvider"
            xmlns="urn:mace:shibboleth:2.0:metadata" id="SPMETADATA"
            metadataFile="/opt/shibboleth-idp/metadata/sp-metadata.xml" />
            
    </metadata:MetadataProvider>

And here is the sp-metadata.xml that is referred to from RelyingParty.xml:

   <EntityDescriptor entityID="https://sp.ejeklint.se/shibboleth" xmlns="urn:oasis:names:tc:SAML:2.0:metadata">
        <!-- The TestShib Two SP supports SAML 2.0, SAML 1.1, and Shibboleth 1.2+. -->
        <SPSSODescriptor
            protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol" xmlns="urn:oasis:names:tc:SAML:2.0:metadata">
            <Extensions xmlns="urn:oasis:names:tc:SAML:2.0:metadata">
                <!-- Extension to permit the SP to receive IdP discovery responses. -->
                <idpdisc:DiscoveryResponse
                    Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"
                    Location="https://sp.ejeklint.se/Shibboleth.sso/Login"
                    index="1" xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"/>
                <idpdisc:DiscoveryResponse
                    Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"
                    Location="https://sp.ejeklint.se/Shibboleth.sso/Login"
                    index="2" xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"/>
            </Extensions>

[verbose key stuff removed...]

            <!-- This tells IdPs that Single Logout is supported and where/how to request it. -->

            <SingleLogoutService
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
                Location="https://sp.ejeklint.se/Shibboleth.sso/SLO/SOAP" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/>
            <SingleLogoutService
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
                Location="https://sp.ejeklint.se/Shibboleth.sso/SLO/Redirect" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/>
            <SingleLogoutService
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
                Location="https://sp.ejeklint.se/Shibboleth.sso/SLO/POST" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/>
            <SingleLogoutService
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"
                Location="https://sp.ejeklint.se/Shibboleth.sso/SLO/Artifact" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/>
            <!-- This tells IdPs that you only need transient identifiers. -->
            <NameIDFormat xmlns="urn:oasis:names:tc:SAML:2.0:metadata">urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
            <NameIDFormat xmlns="urn:oasis:names:tc:SAML:2.0:metadata">urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
            <!--
		This tells IdPs where and how to push assertions through the browser. Mostly
		the SP will tell the IdP what location to use in its request, but this
		is how the IdP validates the location and also figures out which
		SAML version/binding to use.
		-->

            <AssertionConsumerService
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
                Location="https://sp.ejeklint.se/Shibboleth.sso/SAML2/POST"
                index="1" isDefault="true" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/>
            <AssertionConsumerService
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
                Location="https://sp.ejeklint.se/Shibboleth.sso/SAML2/POST-SimpleSign"
                index="2" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/>
            <AssertionConsumerService
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"
                Location="https://sp.ejeklint.se/Shibboleth.sso/SAML2/Artifact"
                index="3" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/>
            <AssertionConsumerService
                Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"
                Location="https://sp.ejeklint.se/Shibboleth.sso/SAML/POST"
                index="4" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/>
            <AssertionConsumerService
                Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"
                Location="https://sp.ejeklint.se/Shibboleth.sso/SAML/Artifact"
                index="5" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/>
	   
      <!-- 
       <AttributeConsumingService index="1">
        <ServiceName xml:lang="en">secure</ServiceName>
       <ServiceDescription xml:lang="en">An example service that requires a human-readable identifier and optional name and e-mail address.</ServiceDescription>
       </AttributeConsumingService> 
       --> 
       </SPSSODescriptor>

        <!-- This is just information about the entity in human terms. -->
        <Organization xmlns="urn:oasis:names:tc:SAML:2.0:metadata">
            <OrganizationName xml:lang="en" xmlns="urn:oasis:names:tc:SAML:2.0:metadata">Shibboleth SP at ejeklint.se</OrganizationName>

            <OrganizationDisplayName xml:lang="en" xmlns="urn:oasis:names:tc:SAML:2.0:metadata">EE SP</OrganizationDisplayName>

            <OrganizationURL xml:lang="en" xmlns="urn:oasis:names:tc:SAML:2.0:metadata">http://www.ejeklint.se</OrganizationURL>
        </Organization>
        <ContactPerson contactType="technical" xmlns="urn:oasis:names:tc:SAML:2.0:metadata">
            <GivenName xmlns="urn:oasis:names:tc:SAML:2.0:metadata">Per</GivenName>
            <SurName xmlns="urn:oasis:names:tc:SAML:2.0:metadata">Ejeklint</SurName>
            <EmailAddress xmlns="urn:oasis:names:tc:SAML:2.0:metadata">mailto:ejeklint at me.com</EmailAddress>

        </ContactPerson>

    </EntityDescriptor>


As for the configuration of the SP, there is indeed a problem with the RequestMapper (I think). The metadata that is available from https://sp.ejeklint.se/Shibboleth.sso/Metadata does indeed have the wrong URLs with www.example.com in them, but as I don't have a metadata provider pointing to that URL it should still work. Or am I ignorant about something here? This is the RequestMapper in shibboleth2.xml which isn't doing what I expect:

    <RequestMapper type="Native">
        <RequestMap>
            <!--
            The example requires a session for documents in /secure on the containing host with http and
            https on the default ports. Note that the name and port in the <Host> elements MUST match
            Apache's ServerName and Port directives or the IIS Site name in the <ISAPI> element above.
            -->
            <Host name="sp.ejeklint.se">
                <Path name="secure" authType="shibboleth" requireSession="true"/>
            </Host>

        </RequestMap>
    </RequestMapper>


Any ideas?


Per Ejeklint
Address: Heimore Group AB, Götgatan 78 22th floor, SE-118 30 Stockholm, Sweden
Phone: +4670-5090052



-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120504/c6177bf6/attachment-0001.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4829 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20120504/c6177bf6/attachment-0001.bin 


More information about the users mailing list