Error Message: SAML 2 SSO profile is not configured for relying party

Brian Tingle Brian.Tingle at ucop.edu
Thu Jul 11 22:20:19 EDT 2013


Thank you so much; that was it!  -- Brian
________________________________________
From: users-bounces at shibboleth.net [users-bounces at shibboleth.net] on behalf of Peter Schober [peter.schober at univie.ac.at]
Sent: Thursday, July 11, 2013 7:11 PM
To: users at shibboleth.net
Subject: Re: Error Message: SAML 2 SSO profile is not configured for relying    party

* Brian Tingle <Brian.Tingle at ucop.edu> [2013-07-12 00:05]:
> 09:56:43.970 - DEBUG
> [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:170]
> - Metadata document contained an EntityDescriptor with the ID
> http://nuxeo-dev.cdlib.org/shibboleth, but it was no longer valid

* Peter Schober <peter.schober at univie.ac.at> [2013-07-12 00:12]:
> > That's the key. How did you get that metadata?

* Brian Tingle <Brian.Tingle at ucop.edu> [2013-07-12 00:22]:
> He says he is getting it from InCommon

The InCommon aggregate contains
"https://nuxeo-dev.cdlib.org/shibboleth" but the error is for
"http://nuxeo-dev.cdlib.org/shibboleth" which does not exist within
InCommon.

So it seems your SP is sending a wrong entityId for itself and/or the
IdP reflects that in locally maintained and expired metadata.

If both your SP and the IdP were using the exact same entityId from
InCommon metadata (and only from there) I don't see how that error
could ever happen.
-peter
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list