SHA1 RelyingParty override not working
Dave Perry
Dave.Perry at hull-college.ac.uk
Thu Aug 11 05:53:57 EDT 2016
I am trying to make an override for one relying party, using the example at https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration.
Said RP has a couple of extra attributes on the SAML2.SSO part - nameIDFormatPrecedence and encryptAssertions, both of which are added to it:
<bean parent="SAML2.SSO" p:securityConfiguration-ref="SHA1SecurityConfig" p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:2.0:nameid-format:email" p:encryptAssertions="false"/>
This then leaves me with an error in the log file, stating that the configuration is invalid:
2016-08-11 09:59:34,240 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeRelyingPartyContextFromSAMLPeer:132] - Profile Action InitializeRelyingPartyContextFromSAMLPeer: Attaching RelyingPartyContext based on SAML peer google.com
2016-08-11 09:59:34,245 - ERROR [net.shibboleth.idp.relyingparty.impl.ReloadingRelyingPartyConfigurationResolver:107] - RelyingPartyResolver 'shibboleth.RelyingPartyConfigurationResolver': error looking up Relying Party: Invalid configuration.
2016-08-11 09:59:34,246 - DEBUG [net.shibboleth.idp.profile.impl.SelectRelyingPartyConfiguration:131] - Profile Action SelectRelyingPartyConfiguration: No relying party configuration applies to this request
2016-08-11 09:59:34,251 - DEBUG [org.opensaml.saml.common.profile.logic.DefaultLocalErrorPredicate:154] - No SAMLBindingContext or binding URI available, error must be handled locally
Any suggestions why?
TIA,
Dave
_________________________________________________
Dave Perry
eLearning Technologist, Hull College Group
Room L34 - Queens Gardens Library
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG
Extension 2230 / Direct Dial 01482 381930
* Need a fast reply? Try elearning at hull-college.ac.uk<mailto:elearning at hull-college.ac.uk> *
**********************************************************************
This message is sent in confidence for the addressee
only. It may contain confidential or sensitive
information. The contents are not to be disclosed
to anyone other than the addressee. Unauthorised
recipients are requested to preserve this
confidentiality and to advise us of any errors in
transmission. Any views expressed in this message
are solely the views of the individual and do not
represent the views of the College. Nothing in this
message should be construed as creating a contract.
Hull College Group owns the email infrastructure, including the contents.
Hull College Group is committed to sustainability, please reflect before printing this email.
**********************************************************************
TEXT
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160811/f46fbe48/attachment.html>
More information about the users
mailing list