no peer endpoint available to which to send SAML response

Brian Tingle Brian.Tingle at ucop.edu
Fri Aug 23 16:03:47 EDT 2013


The campus sponsor put me in touch with the campus IdP who explained to me the error is with the metadata my UCOP identity group registered for me with InCommon.

Sent from my iPhone

On Aug 22, 2013, at 5:53 PM, "Brian Tingle" <Brian.Tingle at ucop.edu<mailto:Brian.Tingle at ucop.edu>> wrote:

Not hearing anything back from UC Trust after filing my paperwork, I have asked around and found out there is an undocumented procedure where I have to try to identify a Shibboleth sponsor on each campus where I need attribute release who can work with the campus IdP to get us set up.

My first campus sponsor reports that they can access one of my applications, but not the other.  For the application where they cannot log in, they report an error "no peer endpoint available to which to send SAML response" and I see messages such as

shib_handler: Invalid HTTP method (GET).
shib_handler: remoted message returned an error: Unable to establish security of incoming assertion.
shib_handler: Unable to establish security of incoming assertion.
shib_handler: remoted message returned an error: Request missing SAMLart query string or form parameter.
shib_handler: Request missing SAMLart query string or form parameter.

in .../log/http/native.log that occured around the time he tried to log in.

there are also entires in transaction.log around the time he tried to log in

2013-08-22 10:24:57 INFO Shibboleth-TRANSACTION [36924]: New session (ID: ) with (applicationId: default) for principal from (IdP: none) at (ClientAddress: 198.108.5.62) with (NameIdentifier: none) using (Protocol: urn:oasis:names:tc:SAML:1.1:protocol) from (AssertionID: )
2013-08-22 10:24:57 INFO Shibboleth-TRANSACTION [36924]: Cached the following attributes with session (ID: ) for (applicationId: default) {
2013-08-22 10:24:57 INFO Shibboleth-TRANSACTION [36924]: }

Can someone please advise me what I can check on my end that might be different between the two services?

I noticed one difference re: SAML2 and SAML1 in the attribute-map.xml -- but I made these files exaclty the same, restarted the shibd and the http -- the the sponsor reports that he is getting the same error.

When the sponsor got the error the second time around, nothing was logged in native.log nor transaction.log, but his attempt was logged in ssl_access.

Or, what should I ask my sponsor to ask his IdP with regard to debugging this issue?

Thanks for your help -- Brian
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130823/0b1a7907/attachment.html 


More information about the users mailing list