TestShib.org: Issue with some URLs specified in the metadata.

Corey Puffalt cplists at gmail.com
Thu Oct 22 13:15:42 EDT 2015


Kevin,

On Thu, Oct 22, 2015 at 10:42 AM, Kevin Foote <kpfoote at uoregon.edu> wrote:

>
>
> > On Oct 22, 2015, at 9:30 AM, Corey Puffalt <cplists at gmail.com> wrote:
> >
> > which helped me understand why a separate self-signed certificate is
> being used for the back-channel endpoints.
> >
> > For testing purposes I hacked the metadata and simply changed the
> endpoints referencing 8443 to 443. Should this work?  (I know it's not
> advisable in a production system, but I'm just trying to validate a basic
> SP configuration).  I'm now seeing errors saying "Inbound message issuer
> was not authenticated." but I'm not sure if this is because I changed the
> port or if there's some other issue related to my SP configuration causing
> the issue.
>
> Cory,
>
> Why are you trying to set up backchannel communication on a newer SP?
>
> You should not be using those endpoints (backchannel) unless you are
> trying to use SAML1 (on purpose, for some reason) and or doing
> AttributeResolution.
>

I'm not purposely trying to use backchannel communication.  My SP (OpenAM
in this case) is configured to use frontchannel communication with
HTTP-POST binding but the SP is performing AttributeResolution over a
backchannel and I don't know how to avoid that?

Corey
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151022/2ebdacc1/attachment-0001.html>


More information about the users mailing list