Initial Setup -- Cannot Get SP and IDP Talking

Sam Agnew saa2012 at qatar-med.cornell.edu
Wed Nov 27 02:54:05 EST 2013


Since we are trying to deliver a service our only interest is solving the issue. As far as I can see the metadata is correct but I base this on my own understanding of the product which is undoubtedly limited.

Here is what makes me think it is correct:

On the SP the shibboleth2.xml file directs the SP to load the IDP metadata from the IDP via URL (https://idpt.qatar-med.cornell.edu/idp/profile/Metadata/SAML). I can see that this is successful in the shibd.log file:
2013-11-26 17:07:26 DEBUG OpenSAML.MetadataProvider.XML : loading configuration from external resource...
2013-11-26 17:07:26 INFO OpenSAML.MetadataProvider.XML : loaded XML resource (https://idpt.qatar-med.cornell.edu/idp/profile/Metadata/SAML)
2013-11-26 17:07:26 DEBUG OpenSAML.MetadataProvider.XML : backing up remote metadata resource to (/var/cache/shibboleth/idp-metadata.xml.c5ed)
2013-11-26 17:07:26 DEBUG OpenSAML.MetadataProvider.XML : committing backup file to permanent location (/var/cache/shibboleth/idp-metadata.xml)
2013-11-26 17:07:26 INFO OpenSAML.MetadataProvider.XML : adjusted reload interval to 7200 seconds

On the IDP the metadata is loaded from file according to idp-process.log:
20:09:43.037 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:253] - Beginning refresh of metadata from '/opt/shibboleth-idp/metadata/idp-metadata.xml'
20:09:43.043 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:257] - Metadata from '/opt/shibboleth-idp/metadata/idp-metadata.xml' has not changed since last refresh
20:09:43.043 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:322] - Computing new expiration time for cached metadata from '/opt/shibboleth-idp/metadata/idp-metadata.xml
20:09:43.044 - INFO [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:271] - Next refresh cycle for metadata provider '/opt/shibboleth-idp/metadata/idp-metadata.xml' will occur on '2013-11-26T20:09:43.039Z' ('2013-11-26T23:09:43.039+03:00' local time)

Comparing a cURL of the xml from that URL (https://idpt.qatar-med.cornell.edu/idp/profile/Metadata/SAML) to the data in the file (/opt/shibboleth-idp/metadata/idp-metadata.xml) reveals that they match.

What I need to do is find out how to get to the bottom of the issue. Where should I look? How can I drill down? This is still a proof of concept build and both IDP and SP are in my hands but I need to reach a working setup so that we can move forward to deploy this for our organisation.

Thanks!

Sam



On Nov 26, 2013, at 5:54 PM, Cantor, Scott wrote:

On 11/26/13, 12:21 AM, "Sam Agnew" <saa2012 at qatar-med.cornell.edu<mailto:saa2012 at qatar-med.cornell.edu>> wrote:

How would I have done that and how can I undo that if I have?

I don't think you did, I'm simply saying I have no other explanation for
you if the metadata's actually correct. So I would have to guess that it's
not. When people swear they've checked, that doesn't generally hold up
under scrutiny. So I would say the IdP metadata isn't what you think it is.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>


--
Sam Agnew
System Administrator
IT Department
Weill Cornell Medical College in Qatar



-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131127/7083a0f0/attachment.html 


More information about the users mailing list