Error in SAML2/POST while Login
Ram, Budh
budh.ram at sap.com
Mon May 9 06:55:44 EDT 2016
Hi,
I am getting below error while browsing this URL http://usphlvm2556.dmzphl.sap.corp:1080/Shibboleth.sso/Login. URL changes to (http://usphlvm2556.dmzphl.sap.corp:1080/Shibboleth.sso/SAML2/POST )
First it try to connect remote metadata provider but connection did not happen then it tries to load my Local copy of metadata file and fail during SAML2/POST operation
SAML response reported an IdP error.
Error from identity provider:
Status: urn:oasis:names:tc:SAML:2.0:status:Requester
Sub-Status: urn:oasis:names:tc:SAML:2.0:status:RequestDenied
Message: The digital signature of the received SAML2 message is invalid.
Native.log file shows below error:
2016-05-09 05:43:32 INFO Shibboleth.DiscoveryFeed : feed files will be cached in C:/opt/shibboleth-sp/var/cache/shibboleth/
2016-05-09 05:43:33 DEBUG Shibboleth.ISAPI [6812] isapi_shib: mapped http://usphlvm2556.dmzphl.sap.corp:1080/Shibboleth.sso/SAML2/POST to default
2016-05-09 05:43:33 DEBUG Shibboleth.ISAPI [6812] isapi_shib_extension: mapped http://usphlvm2556.dmzphl.sap.corp:1080/Shibboleth.sso/SAML2/POST to default
2016-05-09 05:43:33 DEBUG Shibboleth.Listener [6812] isapi_shib_extension: sending message (default/SAML2/POST)
2016-05-09 05:43:33 DEBUG Shibboleth.Listener [6812] isapi_shib_extension: send completed, reading response message
2016-05-09 05:43:33 ERROR Shibboleth.Listener [6812] isapi_shib_extension: remoted message returned an error: SAML response reported an IdP error.
2016-05-09 05:43:33 ERROR Shibboleth.ISAPI [6812] isapi_shib_extension: SAML response reported an IdP error.
While Shibd.log shows below error:
2016-05-09 05:43:32 INFO Shibboleth.Application : building MetadataProvider of type XML...
2016-05-09 05:43:32 INFO OpenSAML.Metadata : building MetadataFilter of type Signature
2016-05-09 05:43:32 INFO XMLTooling.SecurityHelper : loading certificate(s) from file (C:/opt/shibboleth-sp/etc/shibboleth/accounts400_idp_cert2.pem)
2016-05-09 05:43:32 INFO XMLTooling.CredentialResolver.File : no private key resolved, usable for verification/trust only
2016-05-09 05:43:42 ERROR XMLTooling.ParserPool : fatal error on line 0, column 0, message: unable to connect socket for URL 'https://accounts400.sap.com/saml2/metadata/accounts.sap.com'
2016-05-09 05:43:42 ERROR OpenSAML.MetadataProvider.XML : error while loading resource (https://accounts400.sap.com/saml2/metadata/accounts.sap.com): XML error(s) during parsing, check log for specifics
2016-05-09 05:43:42 WARN OpenSAML.MetadataProvider.XML : adjusted reload interval to 600 seconds
2016-05-09 05:43:42 WARN OpenSAML.MetadataProvider.XML : trying backup file, exception loading remote resource: XML error(s) during parsing, check log for specifics
2016-05-09 05:43:42 INFO OpenSAML.MetadataProvider.XML : using local backup of remote resource
2016-05-09 05:43:42 INFO OpenSAML.MetadataProvider.XML : loaded XML resource (C:/opt/shibboleth-sp/var/cache/shibboleth/metadata.xml)
2016-05-09 05:43:42 INFO OpenSAML.Metadata : applying metadata filter (Signature)
2016-05-09 05:43:42 INFO Shibboleth.Application : no TrustEngine specified or installed, using default chain {ExplicitKey, PKIX}
Please help me out in this.
Thanks in advance.
Regards,
Budh Ram
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160509/c4057819/attachment-0001.html>
More information about the users
mailing list