New Shibboleth daemon on new server - user/wayf page just reloads over and over
Ben Turner
bturner at educause.edu
Fri Sep 20 10:12:44 EDT 2013
Hello
So following up we did update our service provider to point to the incommon discovery service. Upon pointing new.educause.edu to https://wayf.incommonfederation.org/DS/WAYF?entityID=https%3A%2F%2Fnew.educause.edu%2Fshibboleth-sp&return=https%3A%2F%2Fnew.educause.edu%2FShibboleth.sso%2FLogin%3FSAMLDS%3D1%26%26target%3Dss%253Amem%253A91141d2bd6a5caee5ad152fa1bcd058582984d82255097e469514ed0790c4ce1
I receive the Invalid Query response when I arrive on the incommon page. Looking into this response further it is describing a missing value in our configuration for <idpdisc:DiscoveryResponse>
however, when I visit our metadata I see that we do have a value for this in our metadata file at https://new.educause.edu/Shibboleth.sso/Metadata which has me confused as to where the value should be that it is missing from. Is there another file that should have that configured or is our entry in the metadata file correct? I haven't seen any other reference to metadata files in the system.
This would appear to point to our underlying issue. This almost strikes me as an install issue. Is that possible that something may have gone afoul in the install process?
Thank you so much for all your assistance!
Ben
________________________________________
From: users-bounces at shibboleth.net [users-bounces at shibboleth.net] on behalf of Cantor, Scott [cantor.2 at osu.edu]
Sent: Wednesday, September 18, 2013 7:15 PM
To: Shib Users
Subject: Re: New Shibboleth daemon on new server - user/wayf page just reloads over and over
On 9/18/13 6:41 PM, "Johnny Lasker" <jlasker at educause.edu> wrote:
>Today, we tried the config that gets generated with testshib and had good
>results. I've attached the config that lets us authenticate against
>testshib and returns us back to our site. It also has a commented out
>section by the SSO and metadataprovider elements showing what we really
>need to use to offer authentication against our pool of Incommon idps.
Using testshib has no material difference from using a real IdP, but what
you're doing there is bypassing discovery. Since the problem here has to
be with your discovery service, that just avoids the issue.
>I checked the transaction log and I see a difference between the two
>settings:
That's not the log I need. Please turn both up to DEBUG and provide a
trace of both native and shibd log when the looping occurs.
>I'm assuming that the lack of a session id is a big factor, would
>something like that be affected by our config settings? Because, if we can
>change from one source to another (our incommon xml vs. testshib) and have
>one generate session ids and the other not, without changing any server
>settings, it seems like we are just missing something with our config.
No, that's a bug of some kind that causes a transaction log entry when
there shouldn't be one. The issue is with your custom discovery code, I am
fairly certain of that.
As a test, something you could try is to point your discoveryURL at the
InCommon discovery service. That might be a good way of teasing something
out.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list