Initial Setup -- Cannot Get SP and IDP Talking
Sam Agnew
saa2012 at qatar-med.cornell.edu
Tue Nov 5 02:25:26 EST 2013
We are trying to set up a new Shibboleth implementation. Initially, we set up an IDP on a Windows 2012 server box with a Centos 6 box as the SP. We were getting the message validation errors that we have read are often a result of time differences. Although we set up NTP on both boxes we thought it might be simpler to configure both IDP and SP on the same Centos box.
We followed a tutorial at: https://wiki.shibboleth.net/confluence/display/SHIB2/IdPInstall
Since we had an SP configured on the Centos box we simply installed the IDP there as well. We can contact the IDP and even its login page (https://unixadmin.qatar-med.cornell.edu/idp/login.jsp) however we cannot get the SP to successfully use the IDP. We get varients on the following:
Please include the following message in any email:
opensaml::saml2md::MetadataException at (https://unixadmin.qatar-med.cornell.edu/secure)
Unable to locate metadata for identity provider (https://unixadmin.qatar-med.cornell.edu/idp/shibboleth)
Simply restarting shibd yields the following in the shibd_warn.log:
2013-11-05 10:19:59 WARN Shibboleth.Application : insecure cookieProps setting, set to "https" for SSL/TLS-only usage
2013-11-05 10:19:59 WARN Shibboleth.Application : handlerSSL should be enabled for SSL/TLS-enabled web sites
2013-11-05 10:19:59 ERROR XMLTooling.libcurl.InputStream : error while fetching https://unixadmin.qatar-med.cornell.edu: (22) The requested URL returned error: 403 Forbidden
2013-11-05 10:19:59 ERROR XMLTooling.ParserPool : fatal error on line 0, column 0, message: internal error in NetAccessor
2013-11-05 10:19:59 ERROR OpenSAML.MetadataProvider.XML : error while loading resource (https://unixadmin.qatar-med.cornell.edu): XML error(s) during parsing, check log for specifics
2013-11-05 10:19:59 WARN OpenSAML.MetadataProvider.XML : adjusted reload interval to 600 seconds
2013-11-05 10:19:59 WARN OpenSAML.MetadataProvider.XML : trying backup file, exception loading remote resource: XML error(s) during parsing, check log for specifics
2013-11-05 10:19:59 ERROR XMLTooling.ParserPool : fatal error on line 0, column 0, message: unable to open primary document entity '/var/cache/shibboleth/idp-metadata.xml'
2013-11-05 10:19:59 ERROR OpenSAML.MetadataProvider.XML : error while loading resource (/var/cache/shibboleth/idp-metadata.xml): XML error(s) during parsing, check log for specifics
2013-11-05 10:19:59 CRIT Shibboleth.Application : error initializing MetadataProvider: XML error(s) during parsing, check log for specifics
As far as we can see, however, the URL works. Visiting the URL (https://unixadmin.qatar-med.cornell.edu/idp/shibboleth) outputs an XML file:
<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0"xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" entityID="https://unixadmin.qatar-med.cornell.edu/idp/shibboleth">
<IDPSSODescriptor protocolSupportEnumeration="urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">
<Extensions>
<shibmd:Scope regexp="false">cornell.edu<http://cornell.edu></shibmd:Scope>
</Extensions>
<KeyDescriptor>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
MIIDaTCCAlGgAwIBAgIURudjUX7LNnISb69BeK0csUrr3OwwDQYJKoZIhvcNAQEF BQAwKjEoMCYGA1UEAxMfdW5peGFkbWluLnFhdGFyLW1lZC5jb3JuZWxsLmVkdTAe Fw0xMzEwMjkxMzExNDlaFw0zMzEwMjkxMzExNDlaMCoxKDAmBgNVBAMTH3VuaXhh ZG1pbi5xYXRhci1tZWQuY29ybmVsbC5lZHUwggEiMA0GCSqGSIb3DQEBAQUAA4IB DwAwggEKAoIBAQCf87C2Uk5ZUgltNmI9XAMVZ8DW4pfRgMMQwQStTxgPUbtvyaJt WOq1EPXlTJw+AvN6YQo0qOCLpf0gVF5jDaBQZ0gIZwWu7cOlKxvAXfAhnpqvrkmz jN4YplSTgg3LuNxGovVHBGqYB76IOI/BwsZtOsH/rwFI4mpDj7zuS2Gv6cOVPiMm 8UJCUoBjsSF6FfaDGTFVSnNNRd3Eke3vzzD7FhPDfXIw33eXtE88t6oEnaz/27xH lRTL3JQpmnBYcoaK1wFH/yOO6HPEbak5Wnq9oVu+f9uUja7cFRsgS+MeO3KEOBku sGxFF+dKmojBbtJhyRaDebknPA/pmRIZ7gotAgMBAAGjgYYwgYMwYgYDVR0RBFsw WYIfdW5peGFkbWluLnFhdGFyLW1lZC5jb3JuZWxsLmVkdYY2aHR0cHM6Ly91bml4 YWRtaW4ucWF0YXItbWVkLmNvcm5lbGwuZWR1L2lkcC9zaGliYm9sZXRoMB0GA1Ud DgQWBBRvtevYFbtFrBIMnwNMqaQak+8a2zANBgkqhkiG9w0BAQUFAAOCAQEAOySG 9jQo2CfX6eC9dSh+TeWWeagfv5+Z5jfJg7iiC2zFg5rQe4ZLpHQjKJgNtvkcQJYy p84Si/m0/aAD6UN+ddYB8J86NCytULJz/SR3Il8KfJuMzOPvfifjyZOZzbEBRwBy Le99al26WANv3wU62DnU/1umsJaqqnDv8Gt63wW6dlRMAhAsueXVgBr2x4NdrnJ0 RomKmPkg21Z2WzUhp4CEBcrez7TH+qLKZ1vcWXPqdS/Lj1Z1C0l/oYv4dZaNPfdJ 5HFI8L58cxpfwbCh8EskMJEz6EvyfcSV9w9CxoHIqbU0/JV7MtShu7fi3jx2ORQy 3ixe+e2BKhXlq29fyQ==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://unixadmin.qatar-med.cornell.edu:8443/idp/profile/SAML1/SOAP/ArtifactResolution"index="1"/>
<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://unixadmin.qatar-med.cornell.edu:8443/idp/profile/SAML2/SOAP/ArtifactResolution"index="2"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://unixadmin.qatar-med.cornell.edu/idp/profile/SAML2/Redirect/SLO"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unixadmin.qatar-med.cornell.edu/idp/profile/SAML2/POST/SLO"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://unixadmin.qatar-med.cornell.edu:8443/idp/profile/SAML2/SOAP/SLO"/>
<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
<NameIDFormat>
urn:oasis:names:tc:SAML:2.0:nameid-format:transient
</NameIDFormat>
<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://unixadmin.qatar-med.cornell.edu/idp/profile/Shibboleth/SSO"/>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unixadmin.qatar-med.cornell.edu/idp/profile/SAML2/POST/SSO"/>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://unixadmin.qatar-med.cornell.edu/idp/profile/SAML2/POST-SimpleSign/SSO"/>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://unixadmin.qatar-med.cornell.edu/idp/profile/SAML2/Redirect/SSO"/>
</IDPSSODescriptor>
<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">
<Extensions>
<shibmd:Scope regexp="false">cornell.edu<http://cornell.edu></shibmd:Scope>
</Extensions>
<KeyDescriptor>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
MIIDaTCCAlGgAwIBAgIURudjUX7LNnISb69BeK0csUrr3OwwDQYJKoZIhvcNAQEF BQAwKjEoMCYGA1UEAxMfdW5peGFkbWluLnFhdGFyLW1lZC5jb3JuZWxsLmVkdTAe Fw0xMzEwMjkxMzExNDlaFw0zMzEwMjkxMzExNDlaMCoxKDAmBgNVBAMTH3VuaXhh ZG1pbi5xYXRhci1tZWQuY29ybmVsbC5lZHUwggEiMA0GCSqGSIb3DQEBAQUAA4IB DwAwggEKAoIBAQCf87C2Uk5ZUgltNmI9XAMVZ8DW4pfRgMMQwQStTxgPUbtvyaJt WOq1EPXlTJw+AvN6YQo0qOCLpf0gVF5jDaBQZ0gIZwWu7cOlKxvAXfAhnpqvrkmz jN4YplSTgg3LuNxGovVHBGqYB76IOI/BwsZtOsH/rwFI4mpDj7zuS2Gv6cOVPiMm 8UJCUoBjsSF6FfaDGTFVSnNNRd3Eke3vzzD7FhPDfXIw33eXtE88t6oEnaz/27xH lRTL3JQpmnBYcoaK1wFH/yOO6HPEbak5Wnq9oVu+f9uUja7cFRsgS+MeO3KEOBku sGxFF+dKmojBbtJhyRaDebknPA/pmRIZ7gotAgMBAAGjgYYwgYMwYgYDVR0RBFsw WYIfdW5peGFkbWluLnFhdGFyLW1lZC5jb3JuZWxsLmVkdYY2aHR0cHM6Ly91bml4 YWRtaW4ucWF0YXItbWVkLmNvcm5lbGwuZWR1L2lkcC9zaGliYm9sZXRoMB0GA1Ud DgQWBBRvtevYFbtFrBIMnwNMqaQak+8a2zANBgkqhkiG9w0BAQUFAAOCAQEAOySG 9jQo2CfX6eC9dSh+TeWWeagfv5+Z5jfJg7iiC2zFg5rQe4ZLpHQjKJgNtvkcQJYy p84Si/m0/aAD6UN+ddYB8J86NCytULJz/SR3Il8KfJuMzOPvfifjyZOZzbEBRwBy Le99al26WANv3wU62DnU/1umsJaqqnDv8Gt63wW6dlRMAhAsueXVgBr2x4NdrnJ0 RomKmPkg21Z2WzUhp4CEBcrez7TH+qLKZ1vcWXPqdS/Lj1Z1C0l/oYv4dZaNPfdJ 5HFI8L58cxpfwbCh8EskMJEz6EvyfcSV9w9CxoHIqbU0/JV7MtShu7fi3jx2ORQy 3ixe+e2BKhXlq29fyQ==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://unixadmin.qatar-med.cornell.edu:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
<AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://unixadmin.qatar-med.cornell.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
<NameIDFormat>
urn:oasis:names:tc:SAML:2.0:nameid-format:transient
</NameIDFormat>
</AttributeAuthorityDescriptor>
</EntityDescriptor>
Sorry this is such a basic question but we are stumped at this point.
Thanks!
Sam
--
Sam Agnew
System Administrator
IT Department
Weill Cornell Medical College in Qatar
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131105/3e955fe1/attachment-0001.html
More information about the users
mailing list