TestShib.org: Issue with some URLs specified in the metadata.
Corey Puffalt
cplists at gmail.com
Thu Oct 22 13:15:42 EDT 2015
Kevin,
On Thu, Oct 22, 2015 at 10:42 AM, Kevin Foote <kpfoote at uoregon.edu> wrote:
>
>
> > On Oct 22, 2015, at 9:30 AM, Corey Puffalt <cplists at gmail.com> wrote:
> >
> > which helped me understand why a separate self-signed certificate is
> being used for the back-channel endpoints.
> >
> > For testing purposes I hacked the metadata and simply changed the
> endpoints referencing 8443 to 443. Should this work? (I know it's not
> advisable in a production system, but I'm just trying to validate a basic
> SP configuration). I'm now seeing errors saying "Inbound message issuer
> was not authenticated." but I'm not sure if this is because I changed the
> port or if there's some other issue related to my SP configuration causing
> the issue.
>
> Cory,
>
> Why are you trying to set up backchannel communication on a newer SP?
>
> You should not be using those endpoints (backchannel) unless you are
> trying to use SAML1 (on purpose, for some reason) and or doing
> AttributeResolution.
>
I'm not purposely trying to use backchannel communication. My SP (OpenAM
in this case) is configured to use frontchannel communication with
HTTP-POST binding but the SP is performing AttributeResolution over a
backchannel and I don't know how to avoid that?
Corey
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151022/2ebdacc1/attachment-0001.html>
More information about the users
mailing list