ECP extension needed for active clients

Mauro Minella Mauro.Minella at microsoft.com
Sat Sep 15 19:19:10 EDT 2012


Hi,

I federated my ShibIdp 2.3.5 with Office365.
Right now the passive logon does work, using the users' upn.

However I need the ECP extension at work in order to connect active clients (like Outlook).
I read that ECP extension is included since 2.3.3 and in fact it seems it's in my version yet.
However, when I try to connect from the active client, I catch the following error in my idp log:
01:08:44.081 - INFO [Shibboleth-Access:74] - 20120915T230844Z|157.56.252.5|shibidp.eduteamit.com:443|/profile/SAML2/SOAP/ECP|
01:08:44.394 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SAML2ECPProfileHandler:408] - REMOTE_USER not set, unable to set principal name
01:08:44.394 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429] - No return endpoint available for relying party urn:federation:MicrosoftOnline

When I set up the federation, I specified the following values:
    $domainName = "shibdomain.eduteamit.com"
    $passiveLogOnUri = "https://shibidp.eduteamit.com/idp/profile/SAML2/POST/SSO"
    $activeLogOnUri = "https://shibidp.eduteamit.com/idp/profile/SAML2/SOAP/ECP"
    $issuerUri = "https://shibidp.eduteamit.com/idp/shibboleth"
    $logOffUrl = "https://shibidp.eduteamit.com/idp/logout"
    $tokenSigningCertificate = "MIIDQDCCAiigAwIBA...=


Where should I look at now, in order to fix this issue?

Thank you,

Mauro
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120915/b7336b63/attachment-0001.html 


More information about the users mailing list