SPSSODescriptor role metadata for entityID could not be resolved
Kevin Foote
kpfoote at uoregon.edu
Fri Jan 9 11:40:35 EST 2015
OK All
Things should be back in working condition now.
Thanks Ken, Simon, and Phil for being patient.
--------
thanks
kevin.foote
> On Jan 9, 2015, at 8:13 AM, Simon Gaeremynck <gaeremyncks at gmail.com> wrote:
>
> If it helps,
>
> I was running into similar problems earlier this week. I had succesfully registered
> and tested our SP with testshib a couple of weeks ago. When doing some more
> work on it this week, the TestShib IdP gave me the same error as Ken is getting.
>
> Assuming TestShib prunes the list of SPs every few weeks, I registered a new entity
> and but when trying to go through the authentication workflow I got the same error.
>
> My entity ids:
> - https://shib-sp.qa0.timetable.grasshopper.fronteer.io/shibboleth
> - https://shib-sp.qa0.timetable.grasshopper.fronteer.io/shibboleth2
>
> Hope that helps!
>
> Simon
>
> PS: Many thanks for the awesome service btw, it’s been super helpful when trying to set things up!
>
>> On 9 Jan 2015, at 16:08, Kevin Foote <kpfoote at uoregon.edu> wrote:
>>
>> Ken -
>> I’ll take a look.
>> Seems you are not alone.
>>
>>
>> FYI put testshib in the subject it helps me out a bunch! :-)
>>
>>
>> --------
>> thanks
>> kevin.foote
>>
>>> On Jan 9, 2015, at 8:06 AM, Ken Swift <swiftk77 at gmail.com> wrote:
>>>
>>> I have been beating my head trying to register my SP with the testshib IdP for the past could of days. I have overhauled my shibboleth2.xml config multiple times and uploaded my metadata, but ever time to try to access my secured directory I get the following error:
>>>
>>> SAML 2 SSO profile is not configured for relying party https://shib.zurigroup.com/shibboleth
>>>
>>> I looked into the IdP logs and get the following details:
>>>
>>> 11:00:15.532 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128] - Looking up relying party configuration for https://shib.zurigroup.com/shibboleth
>>>
>>> 11:00:15.532 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134] - No custom relying party configuration found for
>>> https://shib.zurigroup.com/shibboleth
>>> , looking up configuration based on metadata groups.
>>> 11:00:15.533 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157] - No custom or group-based relying party configuration found for
>>> https://shib.zurigroup.com/shibboleth
>>> . Using default relying party configuration.
>>> 11:00:15.533 - WARN [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:81] - SPSSODescriptor role metadata for entityID '
>>> https://shib.zurigroup.com/shibboleth
>>> ' could not be resolved
>>> 11:00:15.534 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:387] - Decoded request from relying party '
>>> https://shib.zurigroup.com/shibboleth
>>> '
>>> 11:00:15.534 - WARN [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:305] - No metadata for relying party
>>> https://shib.zurigroup.com/shibboleth, treating party as anonymous
>>> I looked on the TestShib.org About/Current Entity List and ensure that my EntityID is listed and it is:
>>>
>>> EntityID https://shib.zurigroup.com/shibboleth
>>>
>>> Anyone have any ideas?
>>>
>>>
>>> For reference here is my metadata:
>>>
>>> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_989e564f01aa0e26eba49692bcfb9685a62e71af" entityID="https://shib.zurigroup.com/shibboleth">
>>>
>>> <md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport">
>>> <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
>>> <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
>>> <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
>>> <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
>>> <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
>>> <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
>>> </md:Extensions>
>>>
>>> <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol">
>>> <md:Extensions>
>>> <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://shib.zurigroup.com/Shibboleth.sso/Login"/>
>>> </md:Extensions>
>>> <md:KeyDescriptor>
>>> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
>>> <ds:KeyName>https://idp.testshib.org/idp/shibboleth</ds:KeyName>
>>> <ds:KeyName>shib.zurigroup.com</ds:KeyName>
>>> <ds:X509Data>
>>> <ds:X509SubjectName>CN=shib.zurigroup.com</ds:X509SubjectName>
>>> <ds:X509Certificate>MIIDJjCCAg6gAwIBAgIJAKf+olmYWxHoMA0GCSqGSIb3DQEBBQUAMB0xGzAZBgNV
>>> BAMTEnNoaWIuenVyaWdyb3VwLmNvbTAeFw0xNTAxMDkwNDEzMjJaFw0yNTAxMDYw
>>> NDEzMjJaMB0xGzAZBgNVBAMTEnNoaWIuenVyaWdyb3VwLmNvbTCCASIwDQYJKoZI
>>> hvcNAQEBBQADggEPADCCAQoCggEBALbRR3ny9hEEV2ut8W4jokvzAnbWL6Z+FCHL
>>> yt/rppTwmVzX0HLwLo+oxzRaW2CkYGXNAc6VAPwawXPmm9oAQNrF8Q/ZUpUn1urs
>>> jMZbjf4Xdio9CfLq2Nokip/+txMf4RpCucAX6jHrq67QkaJfYFbmjiqYXNq3mZxe
>>> jx6J6tS32CZQC4k6+IpgMofCwFecwqjqnwAIM/Y60PdRjuIqwbkHBADEMkXmGkq3
>>> uviydm3trNUO9oa8pYpwbZ8ClLYHG5HVRxJs2SL7QX4PRH6KrrEgkI/EG0QvaWyq
>>> Me5XVPF7du3WF86/+VMR1VlrSDcPHj1/Ct5YvxcvCFTxT2RJuOMCAwEAAaNpMGcw
>>> RgYDVR0RBD8wPYISc2hpYi56dXJpZ3JvdXAuY29thidodHRwczovL2lkcC50ZXN0
>>> c2hpYi5vcmcvaWRwL3NoaWJib2xldGgwHQYDVR0OBBYEFEhSSSTn6XlmnITYjLGQ
>>> LYjoR9lxMA0GCSqGSIb3DQEBBQUAA4IBAQAmNeU2pC/RatTwr3CicLEa/KB/RSl7
>>> Iff88J/+1OwHY3izVv2+8OQmjCy/nP8Bnco8XsNz2O3OqNvXISG0dpKu75lNBHzs
>>> vPK0qfoP2FPUwXkrJ24pQRt35FtrHAq/uSf+NMuupZdHq7yWoc5eTCBKekjFMD8I
>>> +3dksquQMGsIwFx2vs9Rg/RbAwgxJO0Ay51f3OBohFNVJsohe9Uf6dqXLi2WXvBQ
>>> I+C58dRZcN+ZQGNSJSVIGqoFcpW+jjf1jc47scUJPssQoECWWRq9vO0nm/5Ca8LB
>>> j1D19y89FUn9SYgL5K/eD7VlJ+jwoT7gTJP/XlxOdw1MhVcoe4OVKM6Z
>>> </ds:X509Certificate>
>>> </ds:X509Data>
>>> </ds:KeyInfo>
>>> <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
>>> <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
>>> <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
>>> <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
>>> <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
>>> <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
>>> <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
>>> <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
>>> <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
>>> </md:KeyDescriptor>
>>> <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://shib.zurigroup.com/Shibboleth.sso/Artifact/SOAP" index="1"/>
>>> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://shib.zurigroup.com/Shibboleth.sso/SLO/SOAP"/>
>>> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://shib.zurigroup.com/Shibboleth.sso/SLO/Redirect"/>
>>> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://shib.zurigroup.com/Shibboleth.sso/SLO/POST"/>
>>> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://shib.zurigroup.com/Shibboleth.sso/SLO/Artifact"/>
>>> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://shib.zurigroup.com/Shibboleth.sso/SAML2/POST" index="1"/>
>>> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://shib.zurigroup.com/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/>
>>> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://shib.zurigroup.com/Shibboleth.sso/SAML2/Artifact" index="3"/>
>>> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://shib.zurigroup.com/Shibboleth.sso/SAML2/ECP" index="4"/>
>>> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://shib.zurigroup.com/Shibboleth.sso/SAML/POST" index="5"/>
>>> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://shib.zurigroup.com/Shibboleth.sso/SAML/Artifact" index="6"/>
>>> </md:SPSSODescriptor>
>>>
>>> </md:EntityDescriptor>
>>> --
>>> Ken Swift
>>> ken at netoutlook.com
>>> --
>>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>>
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list