Error on Testshib.org IdP server: SPSSODescriptor role metadata ... could not be resolved

McNeill, Stu Stu.McNeill at landesk.com
Thu Jul 2 07:31:52 EDT 2015


Ah yes I see that now.  If I had to guess I’d say there is a dodgy metadata file uploaded with “*.pccc.edu” somewhere it shouldn’t be (in the Entity ID maybe?) which is blocking any new uploads since then.

Let’s hope someone can find a solution.  In the meantime I’m going to try setting up my own IdP, wish me luck!

Thanks
Stu

From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Paul Dixon
Sent: 02 July 2015 10:13
To: Shib Users
Subject: Re: Error on Testshib.org IdP server: SPSSODescriptor role metadata ... could not be resolved

Sounds related to the problem I posted about an hour ago - I traced to back to errors when the metadata is submitted.

Paul

On 2 July 2015 at 09:51, McNeill, Stu <Stu.McNeill at landesk.com<mailto:Stu.McNeill at landesk.com>> wrote:
Hi everyone,

I’m just trying to test Shibboleth for the first time and using the very useful testshib.org<http://testshib.org> to try hosting the SP and connecting to the Testshib IdP.  I can register OK and see my entity ID appear on http://testshib.org/entities.html but when I try to access my “/secure” page I get an error page with message “SAML 2 SSO profile is not configured for relying party (my entity ID) “ and looking at the error log I see these details:

04:34:28.001 - INFO [Shibboleth-Access:73] - 20150702T083428Z|194.168.134.23|idp.testshib.org:443|/profile/SAML2/Redirect/SSO|
04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:86] - shibboleth.HandlerManager: Looking up profile handler for request path: /SAML2/Redirect/SSO
04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:97] - shibboleth.HandlerManager: Located profile handler of the following type for the request path: edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler
04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:339] - LoginContext key cookie was not present in request
04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:188] - Incoming request does not contain a login context, processing as first leg of request
04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:366] - Decoding message with decoder binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect'
04:34:28.007 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128] - Looking up relying party configuration for (my entity ID)
04:34:28.007 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134] - No custom relying party configuration found for (my entity ID), looking up configuration based on metadata groups.
04:34:28.007 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157] - No custom or group-based relying party configuration found for (my entity ID). Using default relying party configuration.
04:34:28.008 - WARN [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:81] - SPSSODescriptor role metadata for entityID '(my entity ID) ' could not be resolved
04:34:28.008 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:387] - Decoded request from relying party '(my entity ID) '
04:34:28.008 - WARN [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:305] - No metadata for relying party (my entity ID), treating party as anonymous
04:34:28.008 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:222] - SAML 2 SSO profile is not configured for relying party (my entity ID)

I’m seeing other people getting the same error and on searching online I found a post to this mailing list from 6 months ago: http://shibboleth.1660669.n2.nabble.com/SPSSODescriptor-role-metadata-for-entityID-could-not-be-resolved-td7610660.html

This seemed to suggest to me there is a problem with the IdP, at least for newly registered SPs.  Any advice to confirm this?  I am asking here because I saw an admin for the site replied and fixed it on their end, could they perform their same magic again?  I couldn’t find any other way to contact the admins.

Thanks
Stu



--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150702/abffe2e2/attachment.html>


More information about the users mailing list