IDP does not find RP Metadata

Ioannis Kakavas ikakavas at noc.grnet.gr
Mon Mar 20 07:43:42 EDT 2017


Strangely enough, we are experiencing the same exactly issue today with
an IdP ( shibboleth IdP v3.3.0) in our federation. The behavior is
exactly as Reiner describes, we can manually grep the ID of the SP in
the cached metadata (and the live online document ) with an SPSSO role
and the DEBUG log is as follows

2017-02-23 11:50:52,959 - DEBUG
[org.opensaml.saml.metadata.resolver.impl.AbstractMetadataResolver:434] -
		Metadata Resolver FileBackedHTTPMetadataResolver HEAL-Link: Metadata
backing store does not contain any EntityDescriptors with the ID:
https://archives.heal-link.gr/shibboleth
2017-02-23 11:50:52,959 - DEBUG
[org.opensaml.saml.metadata.resolver.impl.AbstractBatchMetadataResolver:161]
-
		Metadata Resolver FileBackedHTTPMetadataResolver HEAL-Link: Resolved 0
candidates via EntityIdCriterion: EntityIdCriterion
[id=https://archives.heal-link.gr/shibboleth]
2017-02-23 11:50:52,960 - DEBUG
[org.opensaml.saml.metadata.resolver.impl.AbstractMetadataResolver:586] -
		Metadata Resolver FileBackedHTTPMetadataResolver HEAL-Link: Candidates
iteration was empty, nothing to filter via predicates
2017-02-23 11:50:52,960 - DEBUG
[org.opensaml.saml.metadata.resolver.impl.PredicateRoleDescriptorResolver:260]
-
		Resolved no EntityDescriptors via underlying MetadataResolver,
returning empty collection
2017-02-23 11:50:52,961 - INFO
[org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler:128] -
		Message Handler:  No metadata returned for
https://archives.heal-link.gr/shibboleth in role
{urn:oasis:names:tc:SAML:2.0:metadata}SPSSODescriptor with protocol
urn:oasis:names:tc:SAML:2.0:protocol


Any ideas are welcome.

//Ioannis

On 20/03/2017 01:18 μμ, Rainer Hoerbe wrote:
> An AuthnRequest from a specific SP leads to a 'metadata not found‘ message, while other SPs work.
> 
> INFO [org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler:128] - Message Handler:  No metadata returned for https://shib.lms-staging.km.co.at/shibboleth in role {urn:oasis:names:tc:SAML:2.0:metadata}SPSSODescriptor with protocol urn:oasis:names:tc:SAML:2.0:protocol
> 
> The metadata provider in metadata-providers.xml is "/opt/md_feed/metadata.xml“. When I grep it for the EntityID the ED is found:
> 
> $ grep https://shib.lms-staging.km.co.at /opt/md_feed/metadata.xml 
> <md:EntityDescriptor entityID="https://shib-lms-staging.km.co.at/shibboleth">
> 
> And it does have a role:
> 
> <md:SPSSODescriptor AuthnRequestsSigned="1" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol">
> 
> The metadata is fresh and there were no warnings from the MetadataResolver. How can I trace this problem? I set idp.loglevel.opensaml=DEBUG, but I do not see what is going on.
> 
>  - Rainer
>   
> 

-- 
------------------------------------------------------------------
Ioannis Kakavas - ikakavas at grnet.gr
Identity and Security Engineer
GRNET Network Operations Centre
Greek Research & Technology Network - http://www.grnet.gr
7, Kifisias Av. 115 23 Athens, Greece
Office: +30 2107474255

PGP Fingerprint: A5AA FB5E 740A 603B FAB1 9920 D70F 0CD5 9DE3 C262
------------------------------------------------------------------

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20170320/aec80e9d/attachment.sig>


More information about the users mailing list