Unable To Resolve "SPSSODescriptor role metadata for entityID XXX could no

Clayton upnyhgb8v6 at snkmail.com
Wed Feb 25 19:58:11 EST 2015


I think I've seen that msg many times and lots of things can cause it. 
Seems like every time there's been something about it in the
idp-process.log file.  Of course we've got logging turned way up from an
incident years ago - just doesn't seem to be a downside to it with our
system & load.

One thing to check the entity ID the SP is actually sending against what
you have in the relying-party.xml file.

And while you're in that file, make sure there's a "<rp:RelyingParty ...>"
element and some form of metadata provider for it.  For us this is usually
a "<metadata:MetadataProvider  ...>" element.

--Clayton



"Shib Users users-at-shibboleth.net |Shib|" <3unnche4it at sneakemail.com> on
Wednesday, February 25, 2015 at 6:19 PM -0500 wrote:
>On 2/25/15, 11:12 PM, "Brett Bieber"  wrote:
>>
>>Here's the info I'm following which describes what's needed to send to 
>>Okta:
>>"Ensure that the Identity Provider passes the following attributes 
>>(case-sensitive): FirstName, LastName, Email."
>>
>>No urn, oids, etc... and their SP metadata includes no requested 
>>attributes.
>>
>>Good luck, and I hope you'll share your progress.
>I don't know if it applies, but for Docusign, I'm releasing an 
>email-valued NameID to Okta.
>(And yes, I need to follow my own advice and document all these vendor 
>configs in the wiki, but I have an excuse.)
>-- Scott
>-- 


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150225/279ee0dd/attachment-0001.html 


More information about the users mailing list