IdP 3.1.1 Unable to resolve outbound message endpoint

Cantor, Scott cantor.2 at osu.edu
Tue Mar 31 23:17:44 EDT 2015


On 4/1/15, 2:09 AM, "Scott Koranda" <skoranda at gmail.com> wrote:


>
>What error condition am I actually hitting and how might I have seen
>it from the log?

I believe that's the old "no peer endpoint available..." message 
translated without the word peer, which I tried to mostly avoid using.

That should be turning into an EndpointResolutionFailed event and mapped 
into an error titled "Unable to Respond".

I didn't think that the OpenSAML DEBUG message about endpoint resolution 
added much to that picture, but I guess it would if you have some 
experience. Mostly it just needs to go on a new "frequent error" page.

>Was my deployment methodology (as it were) incorrect and should I have
>attempted to configure attribute resolution and filtering away from
>the defaults before checking that I could make authentication work? Or
>(more likely), have I just missed something simple?

Kind of depends what the test service is or can handle. If you can get a 
test to do something useful with no attributes, it's fine. As always, 
we're hobbled by the assumption that it can get the SP metadata to do any 
testing, which adds a step no matter what.

I probably will work on some kind of "resolvertest" equivalent that can 
exercise authentication in some way from the command line to make testing 
just that piece possible, because the Password handler automatically picks 
up basic-auth credentials now and reuses whatever back-end the form would 
use.

-- Scott



More information about the users mailing list