Centralized Discovery Service - "The Discovery Service should not be called directly"

Christian Munive christian.munive at gmail.com
Wed Jul 23 15:37:39 EDT 2014


Thanks a lot, Scott! I knew I missed something... when I changed the
discoveryURL parameter to cdsserver.inca.net.pe/cds/WAYF, it did reach the
proper page. It's not loading my two IdP's in the list though... I'm going
to try to find the problem.

As a side comment... would you recommend a WAYF solution, like the one from
Switch (https://www.switch.ch/aai/support/tools/wayf.html), instead of a
Shibboleth CDS?


2014-07-23 13:07 GMT-05:00 Cantor, Scott <cantor.2 at osu.edu>:

> On 7/23/14, 1:22 PM, "Christian Munive" <christian.munive at gmail.com>
> wrote:
>
> >Hi everyone. I'm new to the user list. I'm trying to set up a federation
> >in my country; I've succesfully installed a test IdP and a test SP (with
> >embedded DS)... but I'm having problems setting up a centralized
> >discovery service.
>
> You might just rethink doing it, they introduce a large number of problems
> and create misconceptions. Discovery can't be moved that far from a
> service without making assumptions that don't hold in practice.
>
> >Now, on the side of the SP, this is the content of the shibboleth2.xml
> >file:
>
> >                        <SSO discoveryProtocol="SAMLDS"
> >
> >discoveryURL="https://cdsserver.inca.net.pe/cds/index.htm">
>
> That's not the location of a CDS endpoint. That should point to /WAYF not
> index.htm
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140723/64f35fa8/attachment.html 


More information about the users mailing list