shibsp::ConfigurationException error

Mike De Lise mdelise at gmail.com
Tue Mar 3 14:29:56 EST 2015


I've put a fresh install idp-metadata.xml in /opt/shibboleth-idp/metadata
and now getting
XML Parsing Error: XML or text declaration not at start of entity
Location: https://pirlx66vm1/idp/shibboleth
Line Number 3, Column 1:<?xml version="1.0" encoding="UTF-8"?>
^

when accessing the idphost/idp/shibboleth


>>Is this because the acl is only for localhost?
>
> Yes, as documented.

The docs talk about
editing AllowedIPs inside /opt/shibboleth-idp/webapp/WEB-INF/web.xml
That file has no reference at all to AllowedIPs.




On Tue, Mar 3, 2015 at 9:42 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 3/2/15, 10:28 PM, "Mike De Lise" <mdelise at gmail.com> wrote:
>>
>>On the IDP box I did wget https://pirlxjira1/Shibboleth.sso/Metadata
>>and put it in /opt/shibboleth-idp/metadata/idp-metadata.xml
>
> That's incorrect. Put it in a separate file.
>
>>The first part of that metadata file looks like the follow:
>><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
>>ID="_8f11a0cd2126cf3e75cf86d49dc98beff68a9dec"
>>entityID="https://pirlx66vm1/idp/shibboleth">
>
> That would be what the original file contained, but that isn't what the
> SP's metadata would contain.
>
>>Should the default /opt/shibboleth-idp/metadata/idp-metadata.xml point
>>to the SP box or itself?
>
> Itself. Ignore it.
>
>>Is this because the acl is only for localhost?
>
> Yes, as documented.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list