Trouble debugging discovery issue
Ken Weiss
ken.weiss at ucop.edu
Thu Jan 30 13:11:19 EST 2014
I reconfigured to use my new EntityDescriptor and metadata, but I'm still
getting 'Error: Invalid Query' from the Discovery Service.
I went to https://dmp2-dev.cdlib.org/Shibboleth.sso/Metadata and generated
new metadata while running my new shibboleth2.xml file. I noticed an
element that appears in the generated metadata that is missing from my
published metadata:
<init:RequestInitiator
xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init"
Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init"
Location="https://dmp2-dev.cdlib.org/Shibboleth.sso/Login"/>
Would the lack of that element result in the 'Invalid Query' error that I
am seeing? I am very dubious, as a search through the entire
InCommon-metadata.xml file found zero occurrences of this element, but I
thought it was worth asking the question. I apologize for what would seem
to be a question I could answer by searching the web, but I traveled down
many twisty little passages about 'RequestInitiator' without finding any
useful documentation.
--Ken
------------------------------------------------------------
Ken Weiss ken.weiss at ucop.edu
UC Office of the President 510-587-6311 (office)
California Digital Library 916-905-6933 (mobile)
UC Curation Center
415 20th Street, 4th Floor
Oakland, CA 94612
On 1/30/14 8:43 AM, "Ken Weiss" <ken.weiss at ucop.edu> wrote:
>I spoke too soon. I had left the system configured to use the old
>EntityDescriptor.
>
>--Ken
>------------------------------------------------------------
>Ken Weiss ken.weiss at ucop.edu
>UC Office of the President 510-587-6311 (office)
>California Digital Library 916-905-6933 (mobile)
>UC Curation Center
>415 20th Street, 4th Floor
>Oakland, CA 94612
>
>
>
>
>
>
>On 1/30/14 8:26 AM, "Ken Weiss" <ken.weiss at ucop.edu> wrote:
>
>>Oh fer cryin' out loud...
>>
>>Sure enough, this morning everything works as expected. I just needed to
>>wait for the DS to get the newer metadata. Thanks, once again, Scott.
>>
>>--Ken
>>------------------------------------------------------------
>>Ken Weiss ken.weiss at ucop.edu
>>UC Office of the President 510-587-6311 (office)
>>California Digital Library 916-905-6933 (mobile)
>>UC Curation Center
>>415 20th Street, 4th Floor
>>Oakland, CA 94612
>>
>>
>>
>>
>>
>>
>>On 1/30/14 8:14 AM, "Ken Weiss" <ken.weiss at ucop.edu> wrote:
>>
>>>Thanks, Scott. I'll go over the code again and see what I can see, and
>>>also try again to confirm that the InCommon DS is running the latest
>>>metadata.
>>>
>>>I don't think I want to get into running my own DS as I'm just a
>>>sysadmin
>>>with a couple of SPs to manage, but I'll talk to our IdP people about
>>>the
>>>idea.
>>>
>>>--Ken
>>>------------------------------------------------------------
>>>Ken Weiss ken.weiss at ucop.edu
>>>UC Office of the President 510-587-6311 (office)
>>>California Digital Library 916-905-6933 (mobile)
>>>UC Curation Center
>>>415 20th Street, 4th Floor
>>>Oakland, CA 94612
>>>
>>>
>>>
>>>
>>>
>>>
>>>On 1/30/14 7:43 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>>>
>>>>On 1/30/14, 10:37 AM, "Ken Weiss" <ken.weiss at ucop.edu> wrote:
>>>>>
>>>>>So you're saying my shibboleth2.xml and metadata files both look OK?
>>>>
>>>>Yes, but I can't spot a typo. There's no way for me to debug anything I
>>>>don't run, ultimately you need logs. Fundamentally you should not rely
>>>>on
>>>>somebody else's DS, that's really the crux of it. A centralized DS is
>>>>an
>>>>anachronism, a failed experiment dating from the earliest days of the
>>>>project.
>>>>
>>>>>The snippet of metadata was cut-and-pasted from the InCommon
>>>>>production
>>>>>aggregate. If I go to
>>>>>http://md.incommon.org/InCommon/InCommon-metadata.xml and it delivers
>>>>>the
>>>>>right metadata, then it's been updated, right?
>>>>
>>>>Not on any particular service, no.
>>>>
>>>>-- Scott
>>>>
>>>>
>>>>--
>>>>To unsubscribe from this list send an email to
>>>>users-unsubscribe at shibboleth.net
>>>
>>>--
>>>To unsubscribe from this list send an email to
>>>users-unsubscribe at shibboleth.net
>>
>>--
>>To unsubscribe from this list send an email to
>>users-unsubscribe at shibboleth.net
>
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net
More information about the users
mailing list