OIOSAML SP demo authenticating against the IdP from testshib.org

Philip Durbin philip_durbin at harvard.edu
Wed Oct 16 16:36:53 EDT 2013


On Wed, Oct 16, 2013 at 3:06 PM, Kevin P. Foote <kpfoote at iup.edu> wrote:
>
> On Wed, 16 Oct 2013, Philip Durbin wrote:
>> In short, the OIOSAML demo app "just works" with metadata from two of
>> the four IdPs I've tried, but the TestShib IdP isn't one of them. If
>> any TestShib folks are listening, I'd be happy to work with you to try
>> to figure out why.
>
> Phil,
>
> Yea let me know.
>
> Direct is fine rather than clutter list..
>
> MD should be MD..

You'd think, but it would seem that OIOSAML might not be respecting
"2.3 Root Elements" of
http://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf
which states: "A SAML metadata instance describes either a single
entity or multiple entities. In the former case, the root element MUST
be <EntityDescriptor>. In the latter case, the root element MUST be
<EntitiesDescriptor>."

I say this because the OIOSAML configuration utility works fine with
metadata that only has one EntityDescriptor element such as
https://shib.oit.duke.edu/duke-metadata-2-signed.xml but fails on
metadata that that has multiple EntityDescriptor elements such as in
http://www.testshib.org/metadata/testshib-providers.xml

I suppose this should be reported as a bug against OIOSAML... I'm
getting some agreement at
http://irclog.greptilian.com/javaee/2013-10-16#i_31506

Anyway, the "fix" the make OIOSAML is to remove the entire
<EntityDescriptor entityID="https://sp.testshib.org/shibboleth-sp">
section of the TestShib metadata file before uploading it to the
OIOSAML configuration utility. Thank you very much to Kevin Foote for
figuring this out!

Phil

-- 
Philip Durbin
Software Developer for http://thedata.org
http://www.iq.harvard.edu/people/philip-durbin


More information about the users mailing list