Limitations of valid entityIDs

Jacob Lundberg jacob at collegenet.com
Wed Jul 2 21:36:41 EDT 2014


Hello all,

We have a customer who just requested an integration using something
very similar to the following entityID for their IdP:

University_of_Heresville:SAML2

However, adding this in the configuration:

            <SessionInitiator type="Chaining" Location="/Login" id="here" relayState="cookie" entityID="University_of_Heresville:SAML2">

Results in the entire SP becoming dysfunctional and the following error
in the logs:

[Wed Jul 02 18:09:17 2014] [crit] XML error(s) during parsing, check log for specifics
[Wed Jul 02 18:09:17 2014] [crit] shib_child_init() failed to load configuration

Restarting the SP is more informative:

2014-07-02 18:11:53 ERROR XMLTooling.ParserPool : error on line 351, column 137, message: value 'University_of_Heresville:SAML2' is invalid anyURI
2014-07-02 18:11:53 ERROR Shibboleth.Config : error while loading resource (/etc/shibboleth/shibboleth2.xml): XML error(s) during parsing, check log for specifics
2014-07-02 18:11:53 FATAL Shibboleth.Config : caught exception while loading configuration: XML error(s) during parsing, check log for specifics configuration is invalid, check console for specific problems

Obviously we can't set up an integration with them using this entityID.
I am curious what sort of response is recommended in this situation.  Is
this considered a Shibboleth-specific limitation or SAML2, etc?  What is
the specific error or limitation?  I guess maybe there is some list of
valid URL method strings and University_of_Heresville is not on the
list, so it can't be followed by a : like it is?

Thanks,
-Jacob

-- 

Jacob Lundberg
Director, IT Services
jacob at collegenet.com
503.290.0100 (voice)
503.973.5252 (fax)
503.901.8343 (cell)



More information about the users mailing list