Error after succeeded authentication

Gilles Badouet badouetg at uni.coventry.ac.uk
Tue Jul 9 05:40:03 EDT 2013


After a succeeded authentication (according to idp-process.log and ldap logs) through Ldap, I am getting "Error: No peer endpoint available to which to send SAML response" when using google chrome browser, and "opensaml::FatalProfileException at (http://ans.247lib.com/Shibboleth.sso/SAML2/POST): Unable to establish security of incoming assertion" when I use Internet explorer.

An extract of corresponding idp-process.log is as below:

10:04:59.030 - INFO [edu.vt.middleware.ldap.jaas.JaasAuthenticator:176] - Authentication succeeded for dn: uid=jean,ou=People,dc=amlib,dc=com
10:04:59.046 - DEBUG [edu.vt.middleware.ldap.auth.SearchDnResolver:108] - Looking up DN using userField
10:04:59.046 - DEBUG [edu.vt.middleware.ldap.auth.SearchDnResolver:193] - Search with the following parameters:
10:04:59.046 - DEBUG [edu.vt.middleware.ldap.auth.SearchDnResolver:194] -   dn = dc=amlib,dc=com
10:04:59.046 - DEBUG [edu.vt.middleware.ldap.auth.SearchDnResolver:195] -   filter = (uid={0})
10:04:59.046 - DEBUG [edu.vt.middleware.ldap.auth.SearchDnResolver:196] -   filterArgs = [jean]
10:04:59.046 - DEBUG [edu.vt.middleware.ldap.auth.SearchDnResolver:197] -   searchControls = javax.naming.directory.SearchControls at 12f2edf
10:04:59.046 - DEBUG [edu.vt.middleware.ldap.auth.SearchDnResolver:198] -   handler = [edu.vt.middleware.ldap.handler.FqdnSearchResultHandler at 1c2a573]
10:04:59.046 - DEBUG [edu.vt.middleware.ldap.jaas.LdapLoginModule:223] - Committed the following principals: [jean[]]
10:04:59.046 - DEBUG [edu.vt.middleware.ldap.jaas.LdapLoginModule:229] - Committed the following roles: []
10:04:59.061 - INFO [Shibboleth-Access:73] - 20130709T090459Z|192.168.0.2|amlib.co.uk|/profile/SAML2/Redirect/SSO|
10:04:59.061 - WARN [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] - Relying party 'https://ans.247lib.com/shibboleth' requested the response to be returned to endpoint with ACS URL 'https://ans.247lib.com/Shibboleth.sso/SAML2/POST'  and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however no endpoint, with that URL and using a supported binding,  can be found in the relying party's metadata
10:04:59.061 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:447] - No return endpoint available for relying party https://ans.247lib.com/shibboleth
10:21:18.041 - INFO [Shibboleth-Access:73] - 20130709T092118Z|192.168.0.2|amlib.co.uk|/profile/SAML2/Redirect/SSO|






The related error message on shibd.log is:


2013-07-09 09:57:57 ERROR XMLTooling.ParserPool : fatal error on line 0, column 0, message: unable to connect socket for URL 'https://amlib.co.uk/idp/profile/Metadata/SAML'

2013-07-09 09:57:57 ERROR OpenSAML.MetadataProvider.XML : error while loading resource (https://amlib.co.uk/idp/profile/Metadata/SAML): XML error(s) during parsing, check log for specifics

2013-07-09 09:57:57 WARN OpenSAML.MetadataProvider.XML : adjusted reload interval to 1800 seconds

2013-07-09 09:57:57 CRIT OpenSAML.MetadataProvider.XML : maintaining existing configuration, error reloading resource (https://amlib.co.uk/idp/profile/Metadata/SAML): XML error(s) during parsing, check log for specifics

2013-07-09 10:22:11 WARN OpenSAML.MessageDecoder.SAML2 [1]: no metadata found, can't establish identity of issuer (https://amlib.co.uk/idp/shibboleth)

2013-07-09 10:22:11 WARN Shibboleth.SSO.SAML2 [1]: no metadata found, can't establish identity of issuer (https://amlib.co.uk/idp/shibboleth)

2013-07-09 10:22:11 WARN Shibboleth.SSO.SAML2 [1]: detected a problem with assertion: Unable to establish security of incoming assertion.

2013-07-09 10:27:34 INFO XMLTooling.StorageService : purged 4 expired record(s) from storage

2013-07-09 10:27:57 INFO OpenSAML.MetadataProvider.XML : reloading remote resource...

2013-07-09 10:27:57 INFO OpenSAML.MetadataProvider.XML : loaded XML resource (https://amlib.co.uk/idp/profile/Metadata/SAML)

2013-07-09 10:27:57 INFO OpenSAML.MetadataProvider.XML : adjusted reload interval to 7200 seconds




Kind regards





Gilles Rubens Badouet

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130709/59caea16/attachment.html 


More information about the users mailing list