destination endpoint did not match the recipient endpoint error
Satheesh Kumar
satheeshvsbk at gmail.com
Tue Aug 22 09:01:05 EDT 2017
Thanks for the reply Joseph Fischetti,
Our SP redirects to* https.*
I guess it will load the IDP's SSO url from the metadata file. In the
metadata the url will be like https://test.shibbolethidp.test.com/idp/....
Kindly let me know whether I am looking into the correct configuration...
Thanks,
Satheesh
On Tue, Aug 22, 2017 at 8:32 AM, Joseph Fischetti <
Joseph.Fischetti at marist.edu> wrote:
> Satheesh,
>
> Did you configure the SP to redirect to http, or https?
>
>
> Joseph Fischetti
> Linux System Administrator
> Marist College
> E-mail: joseph.fischetti at marist.edu
>
>
>
> ----- Original message -----
> From: Satheesh Kumar <satheeshvsbk at gmail.com>
> Sent by: "users" <users-bounces at shibboleth.net>
> To: Shib Users <users at shibboleth.net>
> Cc:
> Subject: destination endpoint did not match the recipient endpoint error
> Date: Tue, Aug 22, 2017 8:23 AM
>
>
> Hi all,
> I am trying to access my test IDPv3.3 via apache proxy through AJP
> port. When I do this I am getting below error:
>
> ERROR [org.opensaml.saml.common.binding.security.impl.
> ReceivedEndpointSecurityHandler:200] - Message Handler: * SAML message
> intended destination endpoint
> 'https://testshibbolethidp.test.com/idp/profile/SAML2/Redirect/SSO
> <https://testshibbolethidp.test.com/idp/profile/SAML2/Redirect/SSO>' did
> not match the recipient endpoint
> 'http://testshibbolethidp.test.com/idp/profile/SAML2/Redirect/SSO
> <http://testshibbolethidp.test.com/idp/profile/SAML2/Redirect/SSO>'*
> 2017-08-22 12:03:37,577 - WARN [net.shibboleth.idp.profile.impl.
> WebFlowMessageHandlerAdaptor:202] - Profile Action
> WebFlowMessageHandlerAdaptor: Exception handling message
>
> *Tomcat connector details-server.xml:*
> <Connector port="8010" maxThreads="50" minSpareThreads="5"
> connectionTimeout="60000" packetSize="[20000]" protocol="AJP/1.3"
> redirectPort="8443" tomcatAuthentic
> ation="false"/>
> <Connector port="8443" protocol="HTTP/1.1" SSLEnabled="true"
> maxThreads="150" scheme="https" secure="true" clientAuth="false"
> sslProtocol="TLS" keystoreFile="conf/
> KeyStore.jks" keystorePass="password"/>
>
> *IDP's entity ID-taken from idp.properties file:*
>
> https://test-shibbolethidp.test.com/idp/shibboleth
>
> Kindly let me know, what I am missing in configuration.
>
> Thanks,
> Satheesh
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
*Best wishes*,
*Satheesh K*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170822/07fedd26/attachment.html>
More information about the users
mailing list