Update from 2.0 to 2.3.8 (No EndPoint)

Nate Klingenstein nate.klingenstein at utah.edu
Tue Mar 1 14:45:15 EST 2016


Tabitha,

I think there are meaningful known vulnerabilities in both of those versions, so I think you’ll be asked to upgrade and the scope of support will be limited, but this one isn’t very mysterious.

The ACS URL requested in the AuthnRequest doesn’t match any known valid recipient in metadata.

You can look at the AuthnRequest value and you can look at their metadata.  They don’t match for some reason.

If this changed in the update, I would suspect either that you had a very old copy of metadata that did work with the AuthnRequest or you accidentally just patched a security vulnerability.  Either explanation would leave me nervous, but you will be able to resolve this by identifying the discrepency and “fixing” the values to be the right, matching ones.

Take care,
Nate.

On Mar 1, 2016, at 12:36, Tabitha O. Locklear <tabithao.locklear at uncp.edu<mailto:tabithao.locklear at uncp.edu>> wrote:

We recently performed an update to our shibboleth system from 2.0 to 2.3. After the update we are no longer able to authenticate to one of our SP. I have checked the metadata file to make sure that it is being read. I removed it and did a wget to retrieve the latest.

The Log file reads:
10:25:26.448 - WARN [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] - Relying party 'https://uncp-stg.saasit.com/' requested the response to be returned to endpoint with ACS URL 'https://uncp-stg.saasit.com/handlers/sso/SamlAssertionConsumerHandler.ashx'  and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however no endpoint, with that URL and using a supported binding,  can be found in the relying party's metadata
10:25:26.449 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429] - No return endpoint available for relying party https://uncp-stg.saasit.com/
10:25:28.012 - INFO [Shibboleth-Access:74] - 20160301T152528Z|152.21.2.152|dev.idp.uncp.edu<http://dev.idp.uncp.edu/>:443|/profile/SAML2/Redirect/SSO|
10:25:28.012 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:86] - shibboleth.HandlerManager: Looking up profile handler for request path: /SAML2/Redirect/SSO
10:25:28.013 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:97] - shibboleth.HandlerManager: Located profile handler of the following type for the request path: edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler

Tabitha O. Locklear
MS Information Technology
Operations & Systems Analyst
Division of Information Technology
University of North Carolina at Pembroke
tabithao.locklear at uncp.edu<mailto:tabithao.locklear at uncp.edu>
Office : 910-775-4039
Fax : 910-521-6649

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160301/37b825ec/attachment-0001.html>


More information about the users mailing list