Error after succeeded authentication
Gilles Badouet
badouetg at uni.coventry.ac.uk
Tue Jul 9 13:06:50 EDT 2013
Thanks Peter,
I can now access the protected resource (even though it is just a simple html page for the moment :) ).
There was a mistyped word in relying-party.xml exactly at the DefaultRelyingParty element.
Kind regards
Gilles Rubens Badouet
Student ID: 3940347
Faculty of Engineering and Computing
MSc Network Computing Course
Mobile: 07424486426
________________________________________
From: users-bounces at shibboleth.net <users-bounces at shibboleth.net> on behalf of users-request at shibboleth.net <users-request at shibboleth.net>
Sent: 09 July 2013 17:00
To: users at shibboleth.net
Subject: users Digest, Vol 25, Issue 52
Send users mailing list submissions to
users at shibboleth.net
To subscribe or unsubscribe via the World Wide Web, visit
http://shibboleth.net/mailman/listinfo/users
or, via email, send a message with subject or body 'help' to
users-request at shibboleth.net
You can reach the person managing the list at
users-owner at shibboleth.net
When replying, please edit your Subject line so it is more specific
than "Re: Contents of users digest..."
Today's Topics:
1. Re: Error after succeeded authentication (Peter Schober)
2. Re: Generating the response ... (Peter Schober)
3. Re: Error after succeeded authentication (Peter Schober)
4. Re: Generating the response ... (Thomas Lionel SMETS (prof))
----------------------------------------------------------------------
Message: 1
Date: Tue, 9 Jul 2013 17:11:10 +0200
From: Peter Schober <peter.schober at univie.ac.at>
Subject: Re: Error after succeeded authentication
To: users at shibboleth.net
Message-ID: <20130709151110.GF24684 at aco.net>
Content-Type: text/plain; charset=us-ascii
* Gilles Badouet <badouetg at uni.coventry.ac.uk> [2013-07-09 16:59]:
> I did the configuration as you recommended. There is no more error
> in idp-process.log after restarting and authentication. When I
> restart the shibd daemon, sp logs also show that the Idp metadata
> has been loaded successfully.
If that's the case than what's in that metadata doesn't match what the
IdP is sending:
> 2013-07-09 15:48:52 WARN OpenSAML.MessageDecoder.SAML2 [2]: no metadata found, can't establish identity of issuer (https://amlib.co.uk/idp:8443/shibboleth)
> 2013-07-09 15:48:52 WARN Shibboleth.SSO.SAML2 [2]: no metadata found, can't establish identity of issuer (https://amlib.co.uk/idp:8443/shibboleth)
> 2013-07-09 15:48:52 WARN Shibboleth.SSO.SAML2 [2]: detected a
> problem with assertion: Unable to establish security of incoming
> assertion.
So what is the IdP's entityID according to the IdP configuration
(relying-party.xml), according to the protocol message (shibd.log on
DEBUG) and according to the SAML metadata on disk at the SP?
-peter
------------------------------
Message: 2
Date: Tue, 9 Jul 2013 17:12:15 +0200
From: Peter Schober <peter.schober at univie.ac.at>
Subject: Re: Generating the response ...
To: users at shibboleth.net
Message-ID: <20130709151215.GG24684 at aco.net>
Content-Type: text/plain; charset=us-ascii
* Thomas Smets <tsmets at a3-system.eu> [2013-07-09 17:09]:
> I based my code [...]
Please use the dev list for coding questions,
-peter
------------------------------
Message: 3
Date: Tue, 9 Jul 2013 17:32:06 +0200
From: Peter Schober <peter.schober at univie.ac.at>
Subject: Re: Error after succeeded authentication
To: users at shibboleth.net
Message-ID: <20130709153206.GJ24684 at aco.net>
Content-Type: text/plain; charset=us-ascii
* Peter Schober <peter.schober at univie.ac.at> [2013-07-09 17:11]:
> * Gilles Badouet <badouetg at uni.coventry.ac.uk> [2013-07-09 16:59]:
> > I did the configuration as you recommended. There is no more error
> > in idp-process.log after restarting and authentication. When I
> > restart the shibd daemon, sp logs also show that the Idp metadata
> > has been loaded successfully.
>
> If that's the case than what's in that metadata doesn't match what the
> IdP is sending:
>
> > 2013-07-09 15:48:52 WARN OpenSAML.MessageDecoder.SAML2 [2]: no metadata found, can't establish identity of issuer (https://amlib.co.uk/idp:8443/shibboleth)
> > 2013-07-09 15:48:52 WARN Shibboleth.SSO.SAML2 [2]: no metadata found, can't establish identity of issuer (https://amlib.co.uk/idp:8443/shibboleth)
> > 2013-07-09 15:48:52 WARN Shibboleth.SSO.SAML2 [2]: detected a
> > problem with assertion: Unable to establish security of incoming
> > assertion.
>
> So what is the IdP's entityID according to the IdP configuration
> (relying-party.xml), according to the protocol message (shibd.log on
> DEBUG) and according to the SAML metadata on disk at the SP?
The entityID from the protocol message is the one listed above
(twice) which will also be what the IdP thinks of itself, and we know
that and that it's not what the SP has in metadata on disk.
The easy answer is to fix what the SP has on disk.
E.g. if you just copied what the IDP created duting install (frmo
$IDP_HOME/metadata/idp-metadata.xml) but changed that later in
relying-party.xml then the file idp-metadata.xml did not reflect those
changes (it's only generated once during install as a starting point).
-peter
------------------------------
Message: 4
Date: Tue, 09 Jul 2013 17:44:52 +0200
From: "Thomas Lionel SMETS (prof)" <tsmets at a3-system.eu>
Subject: Re: Generating the response ...
To: Shib Users <users at shibboleth.net>
Message-ID: <51DC2FF4.3020109 at a3-system.eu>
Content-Type: text/plain; charset="iso-8859-1"
Don't worry ...
:)
I think I deleted the mails from my MailBox ... & I reposted on the DEV list
\T,
On 09/07/13 17:12, Peter Schober wrote:
> * Thomas Smets <tsmets at a3-system.eu> [2013-07-09 17:09]:
>> I based my code [...]
> Please use the dev list for coding questions,
> -peter
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
Thomas Lionel SMETS, CISSP (385434)
*m :* +32 497 44 68 12
*ph :* +32 2 852 3341
*skype :* thomas.lionel.smets
PGP = FDF0 8FB8 4F37 3F79 1011 05AB 0DCE 9BAB 5DD0 0E10
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130709/04b7b0b3/attachment-0001.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: tsmets.vcf
Type: text/x-vcard
Size: 306 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20130709/04b7b0b3/attachment-0001.vcf
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 552 bytes
Desc: OpenPGP digital signature
Url : http://shibboleth.net/pipermail/users/attachments/20130709/04b7b0b3/attachment-0001.bin
------------------------------
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
End of users Digest, Vol 25, Issue 52
*************************************
More information about the users
mailing list