Issues getting PagerDuty which uses SAML 2.0 to talk to Shibboleth IDP.

Cahill, Charles (GE Appliances) Charles.Cahill at ge.com
Fri Jul 17 18:18:22 EDT 2015


Finally,  I have the IDP Login page coming up... shew !!!



Now, another error to deal with.  Can you guys see what is going on here?



18:05:57.761 [http-bio-8443-exec-7] DEBUG o.o.s.b.AuthnResponseEndpointSelector - Filtering peer endpoints.  Supported peer endpoint bindings: [urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign, urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST, urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact]

18:05:57.761 [http-bio-8443-exec-7] DEBUG o.o.s.b.AuthnResponseEndpointSelector - Removing endpoint https://xxx.pagerduty.com/Shibboleth.sso/SAML2/ECP because its binding urn:oasis:names:tc:SAML:2.0:bindings:PAOS is not supported

18:05:57.761 [http-bio-8443-exec-7] DEBUG o.o.s.b.AuthnResponseEndpointSelector - Removing endpoint https://xxx.pagerduty.com/sso/saml/consume because its binding urn:oasis:names:tc:SAML:2.0:bindings:HTTPS-POST is not supported

18:05:57.762 [http-bio-8443-exec-7] DEBUG o.o.s.b.AuthnResponseEndpointSelector - Selecting endpoint by ACS URL 'https://xxx.pagerduty.com/sso/saml/consume' and protocol binding 'null' for request '_f1bab130-0efd-0133-677c-22000adc166c' from entity 'https://xxx.pagerduty.com'

18:05:57.762 [http-bio-8443-exec-7] DEBUG o.o.s.b.AuthnResponseEndpointSelector - Endpoint with Location 'https://xxx.pagerduty.com/Shibboleth.sso/SAML2/POST/SSO' discarded because neither its Location nor ResponseLocation match ACS URL 'https://xxx.pagerduty.com/sso/saml/consume'

18:05:57.762 [http-bio-8443-exec-7] DEBUG o.o.s.b.AuthnResponseEndpointSelector - Endpoint with Location 'https://xxx.pagerduty.com/Shibboleth.sso/SAML2/POST-SimpleSign' discarded because neither its Location nor ResponseLocation match ACS URL 'https://xxx.pagerduty.com/sso/saml/consume'

18:05:57.762 [http-bio-8443-exec-7] DEBUG o.o.s.b.AuthnResponseEndpointSelector - Endpoint with Location 'https://xxx.pagerduty.com/Shibboleth.sso/SAML2/Artifact' discarded because neither its Location nor ResponseLocation match ACS URL 'https://xxx.pagerduty.com/sso/saml/consume'

18:05:57.762 [http-bio-8443-exec-7] WARN  o.o.s.b.AuthnResponseEndpointSelector - Relying party 'https://xxx.pagerduty.com' requested the response to be returned to endpoint with ACS URL 'https://xxx.pagerduty.com/sso/saml/consume'  and binding 'any' however no endpoint, with that URL and using a supported binding,  can be found in the relying party's metadata

18:05:57.762 [http-bio-8443-exec-7] ERROR e.i.m.s.i.p.AbstractSAMLProfileHandler - No return endpoint available for relying party https://xxx.pagerduty.com

18:05:57.865 [http-bio-8443-exec-7] TRACE e.i.m.s.idp.util.HttpServletHelper - Looking up LoginContext with key c821c3d14eb5389906e9e7f9af6e91a5c0fdf12d69c1a86b9efca48f9c3758a1 from StorageService parition: loginContexts

18:05:57.865 [http-bio-8443-exec-7] DEBUG e.i.m.s.idp.util.HttpServletHelper - No login context in storage service

18:05:57.865 [http-bio-8443-exec-7] DEBUG e.i.m.s.idp.ui.ServiceContactTag - No relying party, nothing to display



Charles Cahill

SSO/LDAP/Web Application Support



Desk 502 452-4737

Cell   502 541-5702

Charles.Cahill at ge.com





-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Thursday, July 16, 2015 2:45 PM
To: Shib Users
Subject: Re: Issues getting PagerDuty which uses SAML 2.0 to talk to Shibboleth IDP.



On 7/16/15, 2:14 PM, "users on behalf of Cahill, Charles (GE Appliances)" <users-bounces at shibboleth.net on behalf of Charles.Cahill at ge.com<mailto:users-bounces at shibboleth.net%20on%20behalf%20of%20Charles.Cahill at ge.com>> wrote:



>Can anyone tell me if I need to change something on the IDP side to get it to talk on https.

>Seems like it only wants to talk on http



Has nothing to do with the IdP, web server configuration is in your hands. If you're offloading SSL, that requires proper configuration of the container, the specifics of which depend on the container. Overriding the scheme and/or port is something you'll have to configure in the connector usually.



-- Scott



--

To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150717/a1487db6/attachment.html>


More information about the users mailing list