Unable To Resolve "SPSSODescriptor role metadata for entityID XXX could no
Clayton
upnyhgb8v6 at snkmail.com
Wed Feb 25 19:58:11 EST 2015
I think I've seen that msg many times and lots of things can cause it.
Seems like every time there's been something about it in the
idp-process.log file. Of course we've got logging turned way up from an
incident years ago - just doesn't seem to be a downside to it with our
system & load.
One thing to check the entity ID the SP is actually sending against what
you have in the relying-party.xml file.
And while you're in that file, make sure there's a "<rp:RelyingParty ...>"
element and some form of metadata provider for it. For us this is usually
a "<metadata:MetadataProvider ...>" element.
--Clayton
"Shib Users users-at-shibboleth.net |Shib|" <3unnche4it at sneakemail.com> on
Wednesday, February 25, 2015 at 6:19 PM -0500 wrote:
>On 2/25/15, 11:12 PM, "Brett Bieber" wrote:
>>
>>Here's the info I'm following which describes what's needed to send to
>>Okta:
>>"Ensure that the Identity Provider passes the following attributes
>>(case-sensitive): FirstName, LastName, Email."
>>
>>No urn, oids, etc... and their SP metadata includes no requested
>>attributes.
>>
>>Good luck, and I hope you'll share your progress.
>I don't know if it applies, but for Docusign, I'm releasing an
>email-valued NameID to Okta.
>(And yes, I need to follow my own advice and document all these vendor
>configs in the wiki, but I have an excuse.)
>-- Scott
>--
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150225/279ee0dd/attachment-0001.html
More information about the users
mailing list