'relying party' error
David Bantz
dabantz at alaska.edu
Tue Aug 26 15:14:26 EDT 2014
On Tue, 26 Aug 2014, at 10:43 , Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 8/26/14, 2:13 PM, "David Bantz" <dabantz at alaska.edu> wrote:
>>
>> I¹m integrating my IdP with a vendor¹s Shibboleth SP. I¹m puzzled by the
>> error he reports is triggered after receiving my IdP¹s SAML:
>
> You're just confused because he's wrong. That's your IdP throwing the
> usual "I have no metadata for the SP" error. He's not receiving anything
> from you by that point.
Ah yes, he didn’t believe or understand my statement that only my DEV/TEST IdP
was configured. Yes, he used the production IdP which doesn’t have the SP metadata
and got “the usual."
(The DEV/TEST IdP does have metadata and responds with good SAML assertion,
which I had dutifully copied before encryption and provided the vendor.)
>> 2) the entityID of my IdP is urn:mace:incommon:alaska.edu but apart from
>> the amusing typo,
>> why would Apache on the service side need my IdP¹s entityID?
>
> To avoid discovery, you give it the IdP to use.
Apache, in addition to or instead of SP’s shibboleth2.xml for which I gave them
exact snippet to consume my IdP metadata?
Further communication from vendor indicates they have the following Apache config snippet:
<Location />
ShibRequestSetting applicationId urn:mace:incommon:alaska.edu
</Location>
Isn’t that supposed to be the name of the vendor’s service instead of my IdP?
(and in any case bad syntax isn’t it? - how could that possibly work?)
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140826/3714b43c/attachment.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20140826/3714b43c/attachment.bin
More information about the users
mailing list