Error Message with IdP "LoginContext key cookie was not present in request"
Patrick Rynhart
P.Rynhart at massey.ac.nz
Sat Jan 4 22:36:09 EST 2014
On 5/01/2014 1:01 p.m., Cantor, Scott wrote:
> On 1/4/14, 6:46 PM, "Mike Flynn" <shibbolethlynda-/E1597aS9LQAvxtiuMwx3w at public.gmane.org> wrote:
>
>> When the error was reported to me by a user at the school I assumed that
>> the school's cert had changed and apprised Ryan about it. Ryan said no
>> change had occurred so I sent him a copy of the metadata I had for their
>> IdP. Ryan said the copy I had matched his production version. Ryan sent
>> me his current production metadata and I checked it as well and it
>> matched. I loaded the copy that Ryan sent to me to my production servers
>> but still the issue persists...
>
> The problem is that comparing any metadata to any other metadata doesn't
> really matter, and it certainly doesn't matter in any way shape or form
> what metadata is *on* the IdP. That's entirely irrelevant.
>
> If you have a piece of metadata that is known to successfully provision a
> working SP, that means something, but there's no such thing as production
> metadata in and of itself. Metadata just describes present configuration,
> and if it doesn't work, then the present configuration doesn't match the
> metadata in use.
>
> The bottom line is that the only way to compare anything is to evaluate
> what the public key in the signature actually is, and then what's in the
> metadata on your end. That's the only thing that matters.
>
> The only other conceivable breaking change is to change the entityID on
> the IdP to something that is still in the metadata at the SP but points to
> a different key.
Is there an "acid test" that I can undertake to verify that the certs
etc. are consistent on the IdP ? What about federating with
testshib.org on our Production box ? What would this prove (in the
context of the problem that we're having federating with Lynda.com) ?
(Aside: We store our certs in CFEngine. I've been back to the 2011
check in, and the files at /opt/shibboleth/credentials on the production
IdP (idp.massey.ac.nz) appear unchanged.)
Thanks,
Patrick
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe-42IIvhcvNBnXOH51mAaJLw at public.gmane.org
>
More information about the users
mailing list