Adding first IDP to Service Provider error

McKean, Brandon Scott - mckeanbs mckeanbs at jmu.edu
Fri Jul 24 11:44:41 EDT 2015


Hi Remi,

That error can come up if entityids don't match up in metadata. If the file you have configured there is in place, I would take a look at it and make sure the entityID is what it should be.

Brandon

On Fri, 2015-07-24 at 10:59 -0400, Remi Mayrand-Provencher wrote:
I finally got both my service provider and my Identity Provider working with testshib so now it is time to make them work together. According to the documentation, I think the only changes I need to make are in shibboleth2.xml to be able to make a basic test. I've tried to link my idp to my sp by modifying those next few things in my shibboleth2.xml file, where "https://test-idp-remi/idp/shibboleth"<https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=> is my idp's entityID.

<SSO entityID="https://test-idp-remi/idp/shibboleth<https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=>">
                SAML2 SAML1
</SSO>

<MetadataProvider type="XML" uri="https://test-idp-remi/idp/shibboleth<https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=>"
             backingFilePath="testRemi-tshib-two-idp-metadata.xml" reloadInterval="180000" />

Still, when I try to reach kohaprod.inlibro.net/Shibboleth.sso/Login, all I get is this :

opensaml::saml2md::MetadataException at (http://kohaprod.inlibro.net/Shibboleth.sso/Login<https://urldefense.proofpoint.com/v2/url?u=http-3A__kohaprod.inlibro.net_Shibboleth.sso_Login&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=6Ge0cflMBzMLVmzSZvAKG4L6HRFV2i9aVtI09U9jkwI&e=>)

Unable to locate metadata for identity provider (https://test-idp-remi/idp/shibboleth<https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=>)


Here is my complete shibboleth2.xml file, if it helps. I took the one from testshib since I just want to try to be redirected to my idp.


<SPConfig xmlns="urn:mace:shibboleth:2.0:native:sp:config" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
    clockSkew="1800">

    <!-- The entityID is the name TestShib made for your SP. -->
    <ApplicationDefaults entityID="https://kohaprod.inlibro.net/shibboleth"<https://urldefense.proofpoint.com/v2/url?u=https-3A__kohaprod.inlibro.net_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=lrNmcWZ-36bS0rgvX_72KKOayQivcADB-UYNkVeZkyM&e=>
        REMOTE_USER="eppn">

        <!-- You should use secure cookies if at all possible.  See cookieProps in this Wiki article. -->
        <!-- https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessions<https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_SHIB2_NativeSPSessions&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=fyyj4GMWmtv_l-MT8lrS7ApAB-NtPsGgED7ptH6As4w&e=> -->
        <Sessions lifetime="28800" timeout="3600" checkAddress="false" relayState="ss:mem" handlerSSL="false">

            <!-- Triggers a login request directly to the TestShib IdP. -->
            <!-- https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPServiceSSO<https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_SHIB2_NativeSPServiceSSO&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=kXUaKziYgJ90IGyq5eYzOcc2q_fM3H7Z2nIyYcns4sI&e=> -->
            <SSO entityID="https://test-idp-remi/idp/shibboleth"<https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=>>
                SAML2 SAML1
            </SSO>

            <!-- SAML and local-only logout. -->
            <!-- https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPServiceLogout<https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_SHIB2_NativeSPServiceLogout&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=4x-fuMpSZGQDVwJtf4_M_KMlgEaN4zNqe76lwtAZSvw&e=> -->
            <Logout>SAML2 Local</Logout>

            <!--
                Handlers allow you to interact with the SP and gather more information.  Try them out!
                Attribute values received by the SP through SAML will be visible at:
                http://kohaprod.inlibro.net/Shibboleth.sso/Session<https://urldefense.proofpoint.com/v2/url?u=http-3A__kohaprod.inlibro.net_Shibboleth.sso_Session&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=oV8vyooAZ5LOMxrTNeoC1FfzRxK7AAUMETfIT4Hf5fQ&e=>
            -->

            <!-- Extension service that generates "approximate" metadata based on SP configuration. -->
            <Handler type="MetadataGenerator" Location="/Metadata" signing="false"/>

            <!-- Status reporting service. -->
            <Handler type="Status" Location="/Status" acl="127.0.0.1"/>

            <!-- Session diagnostic service. -->
            <Handler type="Session" Location="/Session" showAttributeValues="true"/>

            <!-- JSON feed of discovery information. -->
            <Handler type="DiscoveryFeed" Location="/DiscoFeed"/>

        </Sessions>

        <!-- Error pages to display to yourself if something goes horribly wrong. -->
        <Errors supportContact="remi.mayrand-provencher at inlibro.com"<mailto:remi.mayrand-provencher at inlibro.com> logoLocation="/shibboleth-sp/logo.jpg"
                styleSheet="/shibboleth-sp/main.css"/>

        <!-- Loads and trusts a metadata file that describes only the Testshib IdP and how to communicate with it. -->
        <MetadataProvider type="XML" uri="https://test-idp-remi/idp/shibboleth"<https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=>
             backingFilePath="testRemi-tshib-two-idp-metadata.xml" reloadInterval="180000" />

        <!-- Attribute and trust options you shouldn't need to change. -->
        <AttributeExtractor type="XML" validate="true" path="attribute-map.xml"/>
        <AttributeResolver type="Query" subjectMatch="true"/>
        <AttributeFilter type="XML" validate="true" path="attribute-policy.xml"/>

        <!-- Your SP generated these credentials.  They're used to talk to IdP's. -->
        <CredentialResolver type="File" key="sp-key.pem" certificate="sp-cert.pem"/>

</ApplicationDefaults>

    <!-- Security policies you shouldn't change unless you know what you're doing. -->
    <SecurityPolicyProvider type="XML" validate="true" path="security-policy.xml"/>

    <!-- Low-level configuration about protocols and bindings available for use. -->
    <ProtocolProvider type="XML" validate="true" reloadChanges="false" path="protocols.xml"/>

</SPConfig>

Are there any changes that I am missing if I want to test being redirected to my idp by accessing kohaprod.inlibro.net/Shibboleth.sso/Login?

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150724/1bd6bd1e/attachment-0001.html>


More information about the users mailing list