No Peer Endpoint...
Dominic Forrest
dom.forrest at gmail.com
Fri Apr 5 15:48:40 EDT 2013
I got that sorted and am now being challenged for credentials by the IDP :)
When I give correct credentials I now get
An error occurred while processing your request. Please contact your helpdesk or user ID office for assistance
This service requires cookies. Please ensure that they are enabled and try your going back to your desired resource and trying to login again.
Use of your browser's back button may cause specific errors that can be resolved by going back to your desired resource and trying to login again.
If you think you were sent here in error, please contact technical support
Error Message: No peer endpoint available to which to send SAML response
and
20:34:14.027 - WARN [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] - Relying party 'https://sp3.martyforrest.com/shibboleth' requested the response to be returned to endpoint with ACS URL 'https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST' and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however no endpoint, with that URL and using a supported binding, can be found in the relying party's metadata
20:34:14.027 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429] - No return endpoint available for relying party https://sp3.martyforrest.com/shibboleth
20:34:35.001 - INFO [Shibboleth-Access:74] - 20130405T193435Z|192.168.3.52|idp3.martyforrest.com:443|/profile/Metadata/SAML|
- which is where I was before reinstalling on Centos. When I eventually get this working I'm going to write this up from start to finish in a way that works with current releases!
SP metadata returned from https://sp3.martyforrest.com/Shibboleth.sso/Metadata as referenced in relying_party and below - I previously posted shibboleth2.xml
Some further help would be appreciated and thank you again for your patience...
Dom
https://sp3.martyforrest.com/Shibboleth.sso/Metadata
<!--
This is example metadata only. Do *NOT* supply it as is without review,
and do *NOT* provide it in real time to your partners.
-->
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_f1db7d762f61b1d3c0f3f8367dc03c9fe611e352" entityID="https://sp3.martyforrest.com/shibboleth">
<md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport">
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
</md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol">
<md:Extensions>
<init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://sp3.martyforrest.com/Shibboleth.sso/Login"/>
<idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://sp3.martyforrest.com/Shibboleth.sso/Login" index="1"/>
</md:Extensions>
<md:KeyDescriptor>
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:KeyName>sp3.martyforrest.com</ds:KeyName>
<ds:X509Data>
<ds:X509SubjectName>CN=sp3.martyforrest.com</ds:X509SubjectName>
<ds:X509Certificate>MIIDAzCCAeugAwIBAgIJAKCXl8N+F2wVMA0GCSqGSIb3DQEBBQUAMB8xHTAbBgNV
BAMTFHNwMy5tYXJ0eWZvcnJlc3QuY29tMB4XDTEzMDQwNTE2NTcxN1oXDTIzMDQw
MzE2NTcxN1owHzEdMBsGA1UEAxMUc3AzLm1hcnR5Zm9ycmVzdC5jb20wggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCjlJ/00b6E9ZomKkDnBFMbfH/4NMUI
Ah7VGlGpH6/s/yqlFzcNZ+7oKpihxJ069E6AQD6fLxWGHZBpP3/olx/mCacskWbd
NT6EZAhENN9+ntW5BVqLKZ33MN/jtrDT/HfKUuCP4ZmQa6XSSmK8lWfTd/ZPQVe5
NvDEEcZQqk2sD1nero601e7ZiN3yq0nwDtTRLvNoxDPojy9v9RZJIXTyskpy1y0D
IVRuAQT7GtXoIk8kP+h9SKOYeGI9khDp9dOthhaHzO7tRYOo0mMefpBUdqlb3+fc
MzuUunXIzwNAvZYnwbzVSA3Kk55Fi4f9BfealSBy5DboObJZ1cKA0Yn7AgMBAAGj
QjBAMB8GA1UdEQQYMBaCFHNwMy5tYXJ0eWZvcnJlc3QuY29tMB0GA1UdDgQWBBTF
zYVY5QYyK6Ph0blhM7xdku/dvzANBgkqhkiG9w0BAQUFAAOCAQEAa9CM5FdTM/5e
zNcfvc1LytaJ3nele729te5tvkalPSzCgEIvVguf5y4OLCZRuL07y9tL5AKqZNWn
vSqGNFL/0pkzveKEDt/sliSPumU+MhYryuv2WzAclkYOOBNqeM3OhBY5i2JL4GrP
xLKeljCyvuytAEgOOFkz2OfILOaiqO/QLvieA0AY/upfIBlurjzH4s+XKlf+KiEm
33FE2EZNlwL7uB61ie9IYnqOnGDj7ek0PeARHbTj871QB4gQL/bmm1nLO+zv9Dn7
Yy3M7clMCSsVwFxppUI5rHykP5Vxm4ejnmp7z08dupszpUnQcokXL4FtkL7j/8yL
tM2IYXCc4A==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
</md:KeyDescriptor>
<md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://sp3.martyforrest.com/Shibboleth.sso/Artifact/SOAP" index="1"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://sp3.martyforrest.com/Shibboleth.sso/SLO/SOAP"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://sp3.martyforrest.com/Shibboleth.sso/SLO/Redirect"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://sp3.martyforrest.com/Shibboleth.sso/SLO/POST"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://sp3.martyforrest.com/Shibboleth.sso/SLO/Artifact"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST" index="1"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/Artifact" index="3"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/ECP" index="4"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://sp3.martyforrest.com/Shibboleth.sso/SAML/POST" index="5"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://sp3.martyforrest.com/Shibboleth.sso/SAML/Artifact" index="6"/>
</md:SPSSODescriptor>
</md:EntityDescriptor>
On 5 Apr 2013, at 20:34, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> On 4/5/13 3:23 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>
>> Whatever config you're using is enforcing a validUntil requirement. Take
>> the filter out that's requiring that, that's the easiest fix for simple
>> testing.
>>
>> I don't know where that came from, unless it's in the defaults.
>
> Indeed it is. I don't think the SP defaults at this point are compatible
> with the IdP's metadata generated at install time. That metadata is
> static, so I'm sure it has no validUntil time set in the file. It's never
> been noted before, surprisingly.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130405/7a8b9824/attachment.html
More information about the users
mailing list