Error on Testshib.org IdP server: SPSSODescriptor role metadata ... could not be resolved
McNeill, Stu
Stu.McNeill at landesk.com
Thu Jul 2 04:51:16 EDT 2015
Hi everyone,
I'm just trying to test Shibboleth for the first time and using the very useful testshib.org to try hosting the SP and connecting to the Testshib IdP. I can register OK and see my entity ID appear on http://testshib.org/entities.html but when I try to access my "/secure" page I get an error page with message "SAML 2 SSO profile is not configured for relying party (my entity ID) " and looking at the error log I see these details:
04:34:28.001 - INFO [Shibboleth-Access:73] - 20150702T083428Z|194.168.134.23|idp.testshib.org:443|/profile/SAML2/Redirect/SSO|
04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:86] - shibboleth.HandlerManager: Looking up profile handler for request path: /SAML2/Redirect/SSO
04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:97] - shibboleth.HandlerManager: Located profile handler of the following type for the request path: edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler
04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:339] - LoginContext key cookie was not present in request
04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:188] - Incoming request does not contain a login context, processing as first leg of request
04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:366] - Decoding message with decoder binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect'
04:34:28.007 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128] - Looking up relying party configuration for (my entity ID)
04:34:28.007 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134] - No custom relying party configuration found for (my entity ID), looking up configuration based on metadata groups.
04:34:28.007 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157] - No custom or group-based relying party configuration found for (my entity ID). Using default relying party configuration.
04:34:28.008 - WARN [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:81] - SPSSODescriptor role metadata for entityID '(my entity ID) ' could not be resolved
04:34:28.008 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:387] - Decoded request from relying party '(my entity ID) '
04:34:28.008 - WARN [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:305] - No metadata for relying party (my entity ID), treating party as anonymous
04:34:28.008 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:222] - SAML 2 SSO profile is not configured for relying party (my entity ID)
I'm seeing other people getting the same error and on searching online I found a post to this mailing list from 6 months ago: http://shibboleth.1660669.n2.nabble.com/SPSSODescriptor-role-metadata-for-entityID-could-not-be-resolved-td7610660.html
This seemed to suggest to me there is a problem with the IdP, at least for newly registered SPs. Any advice to confirm this? I am asking here because I saw an admin for the site replied and fixed it on their end, could they perform their same magic again? I couldn't find any other way to contact the admins.
Thanks
Stu
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150702/f38abe9c/attachment.html>
More information about the users
mailing list