Limitations of valid entityIDs
Jacob Lundberg
jacob at collegenet.com
Wed Jul 2 21:36:41 EDT 2014
Hello all,
We have a customer who just requested an integration using something
very similar to the following entityID for their IdP:
University_of_Heresville:SAML2
However, adding this in the configuration:
<SessionInitiator type="Chaining" Location="/Login" id="here" relayState="cookie" entityID="University_of_Heresville:SAML2">
Results in the entire SP becoming dysfunctional and the following error
in the logs:
[Wed Jul 02 18:09:17 2014] [crit] XML error(s) during parsing, check log for specifics
[Wed Jul 02 18:09:17 2014] [crit] shib_child_init() failed to load configuration
Restarting the SP is more informative:
2014-07-02 18:11:53 ERROR XMLTooling.ParserPool : error on line 351, column 137, message: value 'University_of_Heresville:SAML2' is invalid anyURI
2014-07-02 18:11:53 ERROR Shibboleth.Config : error while loading resource (/etc/shibboleth/shibboleth2.xml): XML error(s) during parsing, check log for specifics
2014-07-02 18:11:53 FATAL Shibboleth.Config : caught exception while loading configuration: XML error(s) during parsing, check log for specifics configuration is invalid, check console for specific problems
Obviously we can't set up an integration with them using this entityID.
I am curious what sort of response is recommended in this situation. Is
this considered a Shibboleth-specific limitation or SAML2, etc? What is
the specific error or limitation? I guess maybe there is some list of
valid URL method strings and University_of_Heresville is not on the
list, so it can't be followed by a : like it is?
Thanks,
-Jacob
--
Jacob Lundberg
Director, IT Services
jacob at collegenet.com
503.290.0100 (voice)
503.973.5252 (fax)
503.901.8343 (cell)
More information about the users
mailing list