Login Authentication page for shibboleth IDP

Santu Ghosh mon.snahasish at gmail.com
Tue Nov 21 06:35:27 EST 2017


Hi David,

I have tried with URL encoding but no luck :(

I observed that when I am trying IDP initiated flow with testshib SP url
https://sp.testshib.org/shibboleth-sp, its working fine.
Full IDP initiated url is :
https://idp.xxxxx.com/idp/profile/SAML2/Unsolicited/SSO?providerId=https://sp.testshib.org/shibboleth-sp
But the same thing is not working when I am using my SP url (although SP
initiated authentication is working fine for my SP).

Now I am really confused where the problem is.

Attaching my full SP metadata xml, could you please verify it once and
suggest me where is the actual issue and how to resolve the same.

-------------------------------
<?xml version="1.0" encoding="UTF-8"?><md:EntityDescriptor
xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
ID="https___shibboleth-sp-xxxxx.com_shibboleth-sp" entityID="
https://shibboleth-sp-xxxxx.com/shibboleth-sp"><ds:Signature xmlns:ds="
http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo><ds:CanonicalizationMethod
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><ds:SignatureMethod
Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/><ds:Reference
URI="#https___shibboleth-sp-xxxxx.com_shibboleth-sp"><ds:Transforms><ds:Transform
Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform
Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms><ds:DigestMethod
Algorithm="http://www.w3.org/2000/09/xmldsig#sha1
"/><ds:DigestValue>OreU/14CANZdlXlhfpOdBwvjv3E=</ds:DigestValue></ds:Reference></ds:SignedInfo><ds:SignatureValue>I0g7LWoPmja4lyu/9HlOeV71rD8djAcSPRVgnEESwMIgcLMR1cacc3HUaztSOE6cwmP+nk/vnfhxdp3mSlMnxlwiJVpODSuBZAdSLcMHKy4W0Ah9205X1ev+HqAEz/7VxPke2/dv1rV4bonvs49MA+qCe54F9XtgfoTeVPY+gDqWMerrtUj9G92p2w0F/VIjE50A==</ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate>MIIDUjCCAjqgAwIBAgIEUOLIQTANBgkqhkiG9w0BAQUFADBrMQswCQYDVQQGEwJGSTEQMA4GA1UE
CBMHVXVzaW1hYTERMA8GA1UEBxMISGVsc2lua2kxGDAWBgNVBAoTD1JNNSBTb2Z0d2FyZSBPeTEM
MAoGA1UECwwDUiZEMQ8wDQYDVQQDEwZhcG9sbG8wHhOksjQN7xoQZLj9xXefxCFQ69FPcFDeEW
bHwSoBy5hLPNALaEUoa5zPDwlixwRjFQTc5XXaRpgIjy/2gsL8+Y5QRhyXnLqgO67BlLYW/GuHE=</ds:X509Certificate></ds:X509Data></ds:KeyInfo></ds:Signature><md:SPSSODescriptor
AuthnRequestsSigned="true" WantAssertionsSigned="true"
protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><md:KeyDescriptor
use="signing"><ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#
"><ds:X509Data><ds:X509Certificate>MIIDUjCCAjqgAwIBAgIEUOLIQTANBgkqhkiG9w0BAQUFADBrMQswCQYDVQQGEwJGSTEQMA4GA1UE
CBMHVXVzaW1hYTERMA8GA1UEBxMISGVsc2lua2kxGDAWBgNVBAoTD1JNNSBTb2Z0d2FyZSBPeTEM
MAoGA1UECwwDUiZEMQ8wDQYDVQQDEwZhcG9sbG8wHhcNMTVQ49zRvi5qWNRttiFQ69FPcFDeEW
bHwSoBy5hLPNALaEUoa5zPDwlixwRjFQTc5XXaRpgIjy/2gsL8+Y5QRhyXnLqgO67BlLYW/GuHE=</ds:X509Certificate></ds:X509Data></ds:KeyInfo></md:KeyDescriptor><md:KeyDescriptor
use="encryption"><ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#
"><ds:X509Data><ds:X509Certificate>MIIDUjCCAjqgAwIBAgIEUOLIQTANBgkqhkiG9w0BAQUFADBrMQswCQYDVQQGEwJGSTEQMA4GA1UE
CBMHVXVzaW1hYTERMA8GA1UEBxMISGVsc2lua2kxGDAWBgNVBAoTD1JNNSBTb2ZFQ69FPcFDeEW
bHwSoBy5hLPNALaEUoa5zPDwlixwRjFQTc5XXaRpgIjy/2gsL8+Y5QRhyXnLqgO67BlLYW/GuHE=</ds:X509Certificate></ds:X509Data></ds:KeyInfo></md:KeyDescriptor><md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="
https://shibboleth-sp-xxxxx.com/shibboleth-sp/saml/SingleLogout"/><md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="
https://shibboleth-sp-xxxxx.com/shibboleth-sp/saml/SingleLogout"/><md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</md:NameIDFormat><md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat><md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat><md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat><md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName</md:NameIDFormat><md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="
https://shibboleth-sp-xxxxx.com/shibboleth-sp/saml/SSO" index="0"
isDefault="true"/><md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="
https://shibboleth-sp-xxxxx.com/shibboleth-sp/saml/SSO"
index="1"/></md:SPSSODescriptor></md:EntityDescriptor>

---------------------------------------

Please help. Many thanks.


Snahasish


On Mon, Nov 20, 2017 at 9:26 PM, David Huebner <david.huebner at daasi.de>
wrote:

> Since you are masking all the relevant URLs please make sure that the
> entityID in the metadata exactly matches the one you try to initiate SSO
> with.
>
> Oh and you probably have to URL-encode the entityID when requesting SSO.
>
> Refer to the examples in https://wiki.shibboleth.net/
> confluence/display/IDP30/UnsolicitedSSOConfiguration
>
>
>
> On 20.11.2017 15:52, Santu Ghosh wrote:
>
> Hi David,
>
> Thanks for your response.
>
> - you did not register the SP in your IdP (i.e. load metadata of the SP)
>      This is working fine if we test SP initiated flow
>
> -the entityID in your URL does not match the entityID in the metadata file
> - you did add the metadata but forgot to reload the
> MetadataResolverService (or just restart Tomcat/Jetty)
>
>     We have done above mentioned two steps every time when we made any
> changed (if necessary) in xml.
>
>
> Our IDP metadata looks like :
>
> <EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="
> http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0"
> xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="https://idp.
> xxxxxxxx.com/idp/shibboleth">
>
>
> And SP metadata looks like :
>
>
> <?xml version="1.0" encoding="UTF-8"?><md:EntityDescriptor
> xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="https___shibboleth-sp.xxxxxxx.com_shibboleth-sp"
> entityID="https://shibboleth-sp.xxxxxxxx.com/shibboleth-sp"><ds:Signature
> xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo><ds:CanonicalizationMethod
> Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><ds:SignatureMethod
> Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/><ds:Reference
> URI="#https___shibboleth-sp.xxxxxxx.com_shibboleth-sp"><ds:Transforms><ds:Transform
> Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform
> Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms><ds:DigestMethod
> Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/><ds:DigestValue>OreU/
> 14CANZdlXlhfpOdBwvjv3E=</ds:DigestValue></ds:Reference></
> ds:SignedInfo><ds:SignatureValue>I0g7LWoPmja4lyu/9H
>
>
> Can you please take a look.
>
> Snahasish
>
>
>
>
> --
> For Consortium Member technical support, see https://wiki.shibboleth.net/
> confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Snahasish Ghosh
System Engineer.
Mobile No- (0)9733960336
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171121/5ede5200/attachment-0001.html>


More information about the users mailing list