Unable To Resolve "SPSSODescriptor role metadata for entityID XXX could not be resolved"

Brett Bieber bieber at unl.edu
Wed Feb 25 18:12:09 EST 2015


Hi Andy,

On Wed, Feb 25, 2015 at 2:58 PM Kanuch, Andrew <Andy.Kanuch at sdstate.edu>
wrote:
>
>  I’m attempting to add a service provider from Okta to our IDP, but I
> have been unable to resolve this error. After connecting to the SP for the
> first time, it’s reroute back to my IDP on the /idp/profile/SAML2/POST/SSO
> page with the error “*Message did not meet security requirements”*.
>

I'm in the same situation, although I may be further along than you. We're
setting up SSO with Adobe for Creative Cloud and Adobe has outsourced their
federated infrastructure to Okta.

As Scott mentioned, I think the metadata for that RP simply isn't loaded.

Once you overcome that issue, I'd be interested to hear how you're handling
their attribute release requirements.

Here's the info I'm following which describes what's needed to send to Okta:
"Ensure that the Identity Provider passes the following attributes
(case-sensitive): FirstName, LastName, Email."

No urn, oids, etc... and their SP metadata includes no requested attributes.

Good luck, and I hope you'll share your progress.

-Brett
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150225/a3b26c8b/attachment.html 


More information about the users mailing list