testshib.org not accepting SP metadata
sskacy
stuart at cabells.com
Fri Dec 19 21:29:07 EST 2014
I’m not able to upload the metadata for my newly installed SP to
testshib.org. It gives me the following error message:
The file you are attempting to upload is not valid metadata. Please correct
any errors and try again.
I’m getting the metadata file from:
http://localhost:26483/Shibboleth.sso/Metadata
I tried using the example metadata from the following URL:
https://wiki.shibboleth.net/confluence/display/SHIB2/MetadataExample
That metadata worked but the metadata file that Shibboleth is generating on
our server will not. Any suggestions from you geniuses would be greatly
appreciated. I’ve included the contents of the metadata file below with the
domain name replaced with “XXXX”:
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
ID="_d6ea0759583094f9b1238a829de04fa72b0d0430"
entityID="http://www.XXXX.com:26483/shibboleth">
<md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport">
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
<alg:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<alg:DigestMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<alg:SigningMethod
Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
</md:Extensions>
<md:SPSSODescriptor
protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:KeyDescriptor>
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:KeyName>w3.cp.local</ds:KeyName>
<ds:X509Data>
<ds:X509SubjectName>CN=w3.cp.local</ds:X509SubjectName>
<ds:X509Certificate>MIIC6DCCAdCgAwIBAgIJAPQh04H2h4qVMA0GCSqGSIb3DQEBBQUAMBYxFDASBgNV
BAMTC3czLmNwLmxvY2FsMB4XDTE0MTIxODIwMjc0NloXDTI0MTIxNTIwMjc0Nlow
FjEUMBIGA1UEAxMLdzMuY3AubG9jYWwwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw
ggEKAoIBAQDYEbGzYTPog67uJL3A0sQS27R0SciFgvk/MT5RFy5T0PCn/+ayNJtq
AWj7MU5pzMQzH3h6Vu/s/Rum90ES0o/PW1b6xwI8lDf0OKuCM5bYy6LWG9GlKAAc
yJtkbCa50DxqhXGfO1w3Dr+lQBKx7MOMALRZQIys2VIqQ6kNHM65+viyYh5jHSyK
0dZH5bvOZ5DSmmPmZwaGzDEwjZ1AJFW3MbcYV1g/SpfkW54z1QC3q0GiiJw3AlIH
Kk/BKy/Se+ah0TMowuzjFa3fuc8ubUmae38RwtUgD1oMGdzc1UbtXLHsf8CkFmJ5
qHIz3x9SilQ3MdDDCeYLA+LJAc0M3f+lAgMBAAGjOTA3MBYGA1UdEQQPMA2CC3cz
LmNwLmxvY2FsMB0GA1UdDgQWBBR8KzRPf5qZydxKyFpkMKW1j8pmTDANBgkqhkiG
9w0BAQUFAAOCAQEAm2fK2RWkzi8DvbvD58qN0ufdIy8eY4LcHwQXQh1+IH0L2twi
kjPa7f9qmv2D7K8Cd4B5bSyBy8rkxaA95h6wp/zk+8jo88TZRNzCOWGMCPRr2nUb
6ziUVQSCyb3qVvcfWAuEoym0cdEK19G7ogMFoAlLTHgPT5SW3rVLh3x+tQg4AA/P
+E/EEQneb71kA47tlkQdjQyTE0SM/ww1sxgg5Yw3BSQtO50ugX8Vhj8HbBEN30ud
FL046fWKPSXGdRFlZ/axWXL1OPpuXxAijnkcNjuT+DczQURFJJqRx95bYJnGBshm
Ke/cnh5pPOf56ShyTjO/ZjrY48FAKqMTyL6tbg==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
<md:EncryptionMethod
Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
<md:EncryptionMethod
Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
<md:EncryptionMethod
Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
<md:EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
<md:EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
<md:EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
<md:EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
<md:EncryptionMethod
Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
<md:EncryptionMethod
Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
</md:KeyDescriptor>
<md:ArtifactResolutionService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
Location="http://www.XXXX.com:26483/Shibboleth.sso/Artifact/SOAP"
index="1"/>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
Location="http://www.XXXX.com:26483/Shibboleth.sso/SLO/SOAP"/>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
Location="http://www.XXXX.com:26483/Shibboleth.sso/SLO/Redirect"/>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Location="http://www.XXXX.com:26483/Shibboleth.sso/SLO/POST"/>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"
Location="http://www.XXXX.com:26483/Shibboleth.sso/SLO/Artifact"/>
</md:SPSSODescriptor>
</md:EntityDescriptor>
--
View this message in context: http://shibboleth.1660669.n2.nabble.com/testshib-org-not-accepting-SP-metadata-tp7610306.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.
More information about the users
mailing list