New Shibboleth daemon on new server - user/wayf page just reloads over and over

Johnny Lasker jlasker at educause.edu
Tue Sep 17 18:34:48 EDT 2013


Thank you for your continued help on this.

Here is what we get with two different approaches:

Test 1
<SSO discoveryProtocol="SAMLDS"
discoveryURL="https://new.educause.edu/user/wayf">
			  SAML2 SAML1
			</SSO>


Loads the WAYF page, when you click a tile, it reloads the WAYF page

Test 2
<SSO discoveryProtocol="WAYF"
discoveryURL="https://new.educause.edu/user/wayf">
			  SAML2 SAML1
			</SSO>

Loads the WAYF page, when you click a tile, it shows this error (from
localhost)


An Unexpected Error Occurred (opensaml::BindingException) The system
encountered an error at Tue Sep 17 16:19:49 2013 To report this problem,
please contact the site administrator at support at educause.edu. Please
include the following message in any email: opensaml::BindingException at
(https://new.educause.edu/Shibboleth.sso/SAML/POST) Invalid HTTP method
(GET).



It sounds like we need to use the SAMLDS version, but the redirect that is
supposed to get picked up doesn't happen...





Johnny Lasker Programmer/Analyst

EDUCAUSE <http://www.educause.edu/>
Uncommon Thinking for the Common Good
282 Century Place, Suite 5000, Louisville, CO 80027
direct: 303.544.5677 | main: 303.449.4430 | educause.edu
<http://www.educause.edu/>





On 9/17/13 11:33 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>On 9/17/13 1:26 PM, "Johnny Lasker" <jlasker at educause.edu> wrote:
>
>>I updated the hardcoded /DS to be /Login and also updated our metadata
>>with incommon to point to /Login.
>
>The metadata part isn't too crucial, it's just a nicety for documentation
>purposes.
>
>>Now, if you go here and click on 'log in with uncommon'
>>https://new.educause.edu/user/login?destination=user/login it redirects
>>to:
>>https://new.educause.edu/user/wayf?shire=https%3A%2F%2Fnew.educause.edu%2
>>F
>>S
>>hibboleth.sso%2FSAML%2FPOST&time=1379438279&target=ss%3Amem%3A6b5a62c4b72
>>2
>>f
>>8a1f1b186d1bd0df2240a248670f4124c8aa758907e59391c5d&providerId=https%3A%2
>>F
>>%
>>2Fnew.educause.edu%2Fshibboleth-sp
>
>That's a legacy WAYF request. You were treating it as a modern DS before,
>so something is off. I don't know anything about your discovery
>implementation, but perhaps it's not compatible with the old protocol.
>
>I don't see how that would be happening unless you set the
>discoveryProtocol to WAYF, though.
>
>>We are trying to get to the wayf page with our org tiles, but it gives us
>>a 'Direct access to this page is not supported' warning.
>
>That error is from your code, I think, so I don't know what it means.
>
>-- scott
>
>
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net



More information about the users mailing list