Error after succeeded authentication

Gilles Badouet badouetg at uni.coventry.ac.uk
Tue Jul 9 13:06:50 EDT 2013


Thanks Peter,

I can now access the protected resource (even though it is just a simple html page for the moment :) ).
There was a mistyped word in relying-party.xml exactly at the DefaultRelyingParty element.





Kind regards





Gilles Rubens Badouet

Student ID: 3940347

Faculty of Engineering and Computing

MSc Network Computing Course

Mobile: 07424486426

________________________________________
From: users-bounces at shibboleth.net <users-bounces at shibboleth.net> on behalf of users-request at shibboleth.net <users-request at shibboleth.net>
Sent: 09 July 2013 17:00
To: users at shibboleth.net
Subject: users Digest, Vol 25, Issue 52

Send users mailing list submissions to
        users at shibboleth.net

To subscribe or unsubscribe via the World Wide Web, visit
        http://shibboleth.net/mailman/listinfo/users
or, via email, send a message with subject or body 'help' to
        users-request at shibboleth.net

You can reach the person managing the list at
        users-owner at shibboleth.net

When replying, please edit your Subject line so it is more specific
than "Re: Contents of users digest..."


Today's Topics:

   1. Re: Error after succeeded authentication (Peter Schober)
   2. Re: Generating the response ... (Peter Schober)
   3. Re: Error after succeeded authentication (Peter Schober)
   4. Re: Generating the response ... (Thomas Lionel SMETS (prof))


----------------------------------------------------------------------

Message: 1
Date: Tue, 9 Jul 2013 17:11:10 +0200
From: Peter Schober <peter.schober at univie.ac.at>
Subject: Re: Error after succeeded authentication
To: users at shibboleth.net
Message-ID: <20130709151110.GF24684 at aco.net>
Content-Type: text/plain; charset=us-ascii

* Gilles Badouet <badouetg at uni.coventry.ac.uk> [2013-07-09 16:59]:
> I did the configuration as you  recommended. There is no more error
> in idp-process.log after restarting and authentication. When I
> restart the shibd daemon, sp logs also show that the Idp metadata
> has been loaded successfully.

If that's the case than what's in that metadata doesn't match what the
IdP is sending:

> 2013-07-09 15:48:52 WARN OpenSAML.MessageDecoder.SAML2 [2]: no metadata found, can't establish identity of issuer (https://amlib.co.uk/idp:8443/shibboleth)
> 2013-07-09 15:48:52 WARN Shibboleth.SSO.SAML2 [2]: no metadata found, can't establish identity of issuer (https://amlib.co.uk/idp:8443/shibboleth)
> 2013-07-09 15:48:52 WARN Shibboleth.SSO.SAML2 [2]: detected a
> problem with assertion: Unable to establish security of incoming
> assertion.

So what is the IdP's entityID according to the IdP configuration
(relying-party.xml), according to the protocol message (shibd.log on
DEBUG) and according to the SAML metadata on disk at the SP?
-peter


------------------------------

Message: 2
Date: Tue, 9 Jul 2013 17:12:15 +0200
From: Peter Schober <peter.schober at univie.ac.at>
Subject: Re: Generating the response ...
To: users at shibboleth.net
Message-ID: <20130709151215.GG24684 at aco.net>
Content-Type: text/plain; charset=us-ascii

* Thomas Smets <tsmets at a3-system.eu> [2013-07-09 17:09]:
> I based my code [...]

Please use the dev list for coding questions,
-peter


------------------------------

Message: 3
Date: Tue, 9 Jul 2013 17:32:06 +0200
From: Peter Schober <peter.schober at univie.ac.at>
Subject: Re: Error after succeeded authentication
To: users at shibboleth.net
Message-ID: <20130709153206.GJ24684 at aco.net>
Content-Type: text/plain; charset=us-ascii

* Peter Schober <peter.schober at univie.ac.at> [2013-07-09 17:11]:
> * Gilles Badouet <badouetg at uni.coventry.ac.uk> [2013-07-09 16:59]:
> > I did the configuration as you  recommended. There is no more error
> > in idp-process.log after restarting and authentication. When I
> > restart the shibd daemon, sp logs also show that the Idp metadata
> > has been loaded successfully.
>
> If that's the case than what's in that metadata doesn't match what the
> IdP is sending:
>
> > 2013-07-09 15:48:52 WARN OpenSAML.MessageDecoder.SAML2 [2]: no metadata found, can't establish identity of issuer (https://amlib.co.uk/idp:8443/shibboleth)
> > 2013-07-09 15:48:52 WARN Shibboleth.SSO.SAML2 [2]: no metadata found, can't establish identity of issuer (https://amlib.co.uk/idp:8443/shibboleth)
> > 2013-07-09 15:48:52 WARN Shibboleth.SSO.SAML2 [2]: detected a
> > problem with assertion: Unable to establish security of incoming
> > assertion.
>
> So what is the IdP's entityID according to the IdP configuration
> (relying-party.xml), according to the protocol message (shibd.log on
> DEBUG) and according to the SAML metadata on disk at the SP?

The entityID from the protocol message is the one listed above
(twice) which will also be what the IdP thinks of itself, and we know
that and that it's not what the SP has in metadata on disk.
The easy answer is to fix what the SP has on disk.

E.g. if you just copied what the IDP created duting install (frmo
$IDP_HOME/metadata/idp-metadata.xml) but changed that later in
relying-party.xml then the file idp-metadata.xml did not reflect those
changes (it's only generated once during install as a starting point).
-peter


------------------------------

Message: 4
Date: Tue, 09 Jul 2013 17:44:52 +0200
From: "Thomas Lionel SMETS (prof)" <tsmets at a3-system.eu>
Subject: Re: Generating the response ...
To: Shib Users <users at shibboleth.net>
Message-ID: <51DC2FF4.3020109 at a3-system.eu>
Content-Type: text/plain; charset="iso-8859-1"


Don't worry ...
:)
I think I deleted the mails from my MailBox ... & I reposted on the DEV list


\T,

On 09/07/13 17:12, Peter Schober wrote:
> * Thomas Smets <tsmets at a3-system.eu> [2013-07-09 17:09]:
>> I based my code [...]
> Please use the dev list for coding questions,
> -peter
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


--
Thomas Lionel SMETS, CISSP (385434)
*m :* +32 497 44 68 12
*ph :* +32 2 852 3341
*skype :* thomas.lionel.smets

PGP = FDF0 8FB8 4F37 3F79 1011 05AB 0DCE 9BAB 5DD0 0E10
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130709/04b7b0b3/attachment-0001.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: tsmets.vcf
Type: text/x-vcard
Size: 306 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20130709/04b7b0b3/attachment-0001.vcf
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 552 bytes
Desc: OpenPGP digital signature
Url : http://shibboleth.net/pipermail/users/attachments/20130709/04b7b0b3/attachment-0001.bin

------------------------------

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

End of users Digest, Vol 25, Issue 52
*************************************



More information about the users mailing list