Receiving unable to locate metadata error for testshib sp for IDP siteminderidp.shaku08.edu

Kunal Shah ks186033 at gmail.com
Wed Jun 20 02:46:04 EDT 2018


Ok so this seems to be fixed now. At least metadata is there and it is
redirecting me to IDP. Now I ran into other problem.

I get error at the SP side after receiving assertion from IDP. Error
says 

xmltooling::UnmarshallingException at (https://www.testshib.org/Shibboleth.sso/SAML2/POST)

Invalid attribute: Id

I tried to take a look at shibd.log and found unnecessory characters in
signature

DAtNYWhhcmFzaHRyYTENMAsGA1UEBwwEUHVuZTETMBEGA1UECgwKS3VuYWwgU2hhaDETMBEGA1UE
AwwKS3VuYWwgU2hhaDEkMCIGCSqGSIb3DQEJARYVZmluZGVyczIwMTRAZ21haWwuY29tMB4XDTE4
MDYxOTE1MDYxMloXDTE5MDYxOTE1MDYxMlowZzELMAkGA1UEBhMCSU4xFDASBgNVBAgMC01haGFy
YXNodHJhMRMwEQYDVQQKDApLdW5hbCBTaGFoMRgwFgYDVQQLDA9zbWlkcHNpZ25pbmdrZXkxEzAR
BgNVBAMMCkt1bmFsIFNoYWgwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDTI4p/7Egu
bFrjaJ3+jY7YtN/IaxniXzTxtpt3QTgMSY0Bat0DshPRcFol3Ds6Izm+X/ois2AntR1KU11+ZQ2k
NYnUNzWmK6SCjg8s1q9ODJ5EgvFeJ+pK7Si/LkOkRRxxkuDfIM+XSsVUrZCdH995rnx3JQYJOXMn
gWVJC9LFlBpgCdy2NwHfzD7WNzld4OfBiu/UgXQg8S3NSdhYm+2KVS9yZEwu4Ov9GouszSYu+EK1
7cN5yOY2pdAdDrX1Y8axqxwzuwRFUvl5TD3I2KzWFG7feiRPlruKym/b3j/KJL+Nzb3BzbiPjPn6
x4CDV+1R6LM+u0JaH8l47Z84caz5AgMBAAGjezB5MAkGA1UdEwQCMAAwLAYJYIZIAYb4QgENBB8W
HU9wZW5TU0wgR2VuZXJhdGVkIENlcnRpZmljYXRlMB0GA1UdDgQWBBRVlTEyWG9sOYcgCvsyIxYr
0AX3kTAfBgNVHSMEGDAWgBQT/5Gb1dOvkxeT/Cg7C77pgzkJszANBgkqhkiG9w0BAQsFAAOCAgEA
lshxsuYklRBDepAlWsCfz61YdHxC+WgBH3S91V7sLHvST14001+fTXCVAiWfYWhO1Mqb1QwuQK7d
p8cgYpttmig/6dp5tDPvxnOL13Q0n03FIES1Xum+zB0PzUsNY84rJdVV0xi1W105z2CYaUqZbJ9o
INfB4xXqfLzDmeSEvnS3RPXs8KwA+xDAxr07aY/cGGFbDxsM8ZG9UcKzEILCCLXVE3WeZxBbpoLW
ADYiIwhqjpp4VtQJ/4bXMk/55xTlF/KCtc88nx8VDqiHLYXjd/ynUjPMgU/h+O5jDugoTLZuLM4P
xMB81E7TASI0Q0W+7anR6M+j+01vsGNY54IXJvgoe4bkS8Xv5K5yVMbGQLAD9X4T0COia6QCirmD
3z0U0J6czvq+0aceP0wKBpahaesIaZ6oLZsMCROvFFa2uuhl4sYlrZXtSJ+VMLI/X9JCANrWHZaI
QEMjpkibSqj+Sye6k2hHW3xiywGfKxHRxJKEcZLvD4q+CXv8w7qhCG+cbeYTqi0PXZ2HZbQfhzYw
wcKh16QgDtI75FrfpQkxcjvTpjsEezEAlAj9hU9gkt8Igf4PRG/oHmj2R0M1AhASbsfATl0D4PWv
eyyEMn179lMcTjOOeOhcodPvCLQv+CEKcyK4+OBo256CUq1N1GUZUIDkXQVXUM0sEzW9mBZR8hU=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
        <ns2:Subject>
            <ns2:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">amaclead at gmail.com</ns2:NameID>
            <ns2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
                <ns2:SubjectConfirmationData InResponseTo="_a3d433b4378b19f9dd7d2011c72cd856" NotOnOrAfter="2018-06-20T06:44:32Z" Recipient="https://www.testshib.org/Shibboleth.sso/SAML2/POST"/>
            </ns2:SubjectConfirmation>
        </ns2:Subject>
        <ns2:Conditions NotBefore="2018-06-20T06:42:32Z" NotOnOrAfter="2018-06-20T06:44:32Z">
            <ns2:AudienceRestriction>
                <ns2:Audience>https://sp.testshib.org/shibboleth-sp</ns2:Audience>
            </ns2:AudienceRestriction>
        </ns2:Conditions>
        <ns2:AuthnStatement AuthnInstant="2018-06-20T06:39:00Z" SessionIndex="QXj+krFV+BUQMVU7nLSmeIeqqlk=GrAd4g==" SessionNotOnOrAfter="2018-06-20T06:44:32Z">
            <ns2:AuthnContext>
                <ns2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</ns2:AuthnContextClassRef>
            </ns2:AuthnContext>
        </ns2:AuthnStatement>
    </ns2:Assertion>
</Response>
2018-06-20 02:43:54 DEBUG Shibboleth.Listener [12]: dispatching message (default::getHeaders::Application)
2018-06-20 02:43:54 DEBUG Shibboleth.Listener [12]: dispatching message (find::StorageService::SessionCache)
2018-06-20 02:43:54 DEBUG XMLTooling.StorageService [12]: updated expiration of valid records in context (_c81469ecc17f81092305f8dea39db8fd) to (1529480634)
2018-06-20 02:44:00 INFO XMLTooling.StorageService : purged 10 expired record(s) from storage

if you see at the end of signature lines there is #13. That is not part
of x509 certificate. Not sure from where it is coming but I suspect that
is the issue. I need to look at IDP side to see what's going on there.

Regards
Kunal Shah


On Wed, Jun 20, 2018 at 05:30:31AM +0000, Kevin Foote wrote:
>Shold be good to go now.
>
>--------
>thanks
> kevin.foote
>
>> On Jun 19, 2018, at 10:33 PM, Kunal Shah <ks186033 at gmail.com> wrote:
>>
>> Hi Nate,
>>
>> It can wait.
>>
>> Thanks
>> Kunal
>> On Tue, Jun 19, 2018 at 09:25:48PM -0700, Nate Klingenstein wrote:
>>> Kunal,
>>>
>>> It's likely that someone uploaded metadata that broke TestShib just before
>>> you did.  I'm candidly too exhausted to go looking for it right now, but if
>>> you can wait until the morning in U.S. time, I'll get this fixed right away.
>>>
>>> Sorry.  This is a volunteer service, and we're doing our best.
>>>
>>> Thanks,
>>> Nate.
>>>
>>> On Tue, Jun 19, 2018 at 9:16 PM, Kunal Shah <ks186033 at gmail.com> wrote:
>>>
>>>> Hello,
>>>>
>>>> I have configured CA SSO 12.8 (https://www.ca.com/us/
>>>> products/ca-single-sign-on.html) as IDP provider. I am planning to test
>>>> testshib.org as SP.
>>>>
>>>> I uploaded IDP metadata and received the message that it is successfully
>>>> uploaded, the file is attached here. It shows me entityid as
>>>> siteminderidp.shaku08.edu. However, when I am trying to test, it gives me
>>>> a message
>>>>
>>>> 2018-06-19 23:40:57 DEBUG Shibboleth.Listener [111]: dispatching message
>>>> (default/TestShib::run::SAML2SI)
>>>> 2018-06-19 23:40:57 WARN Shibboleth.SessionInitiator.SAML2 [111]: unable
>>>> to locate metadata for provider (siteminderidp.shaku08.edu)
>>>> I am not sure why I am receiving message although I have successfully
>>>> uploaded metadata with proper entityID.
>>>>
>>>> link to my idp metadata https://pastebin.com/2rMkgHqY
>>>>
>>>> Thanks
>>>> --
>>>> For Consortium Member technical support, see https://wiki.shibboleth.net/
>>>> confluence/x/coFAAg
>>>> To unsubscribe from this list send an email to
>>>> users-unsubscribe at shibboleth.net
>>>>
>>
>>> --
>>> For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
>>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>>
>> --
>> For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
>-- 
>For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
>To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list