Receiving unable to locate metadata error for testshib sp for IDP siteminderidp.shaku08.edu
Kunal Shah
ks186033 at gmail.com
Wed Jun 20 11:49:36 EDT 2018
The error I posted was to my SP. I am testing IDP to SP. IDP is CA SSO
generating SAML Assertions after authentication.
I started with pointing it to testshib SP so that I can check if IDP is
giving proper response. I found error. Since I didn't have more logs, I
setup shibboleth SP on my other centos server and enabled debug logs.
Didn't find much in shibd.log but ssl error log in SP's
/var/log/httpd/ssl_error_log
file makes these entries.
[Wed Jun 20 14:28:38.091829 2018] [mod_shib:error] [pid 1251] [client
123.201.54.30:18945] Invalid attribute: Id, referer:
https://cassoidp.shaku08.edu/affwebservices/public/saml2sso?SMASSERTIONREF=QUERY&SAMLRequest=fZJNU4MwFEX%2FCpN9CY1SSqYwg%2B3CzlTt2OrCjRPgVTJCgrzE6r83gB910204uTf3DAsUTd3yzJpK3cObBTTeR1Mr5MOHhNhOcS1QIleiAeSm4LvsZsOZH%2FC200YXuiZehgidkVottULbQLeD7l0W8HC%2FSUhlTIucUqxkjm0JjfaN6%2FGhtHTnznJdg6l8RE37aEa3d7s98VaOkUr0qX8ZhXCYLFsfK%2FFqg%2FkQIg6HI%2BQ4ViJtbV7LgvYDmKOJt14l5DkI4%2FhChBDnRRjF85AFBYSHQySiGYvzMHIYooW1QiOUSQgLpvNJMJuwYD%2B95Czi4fyJeNvvyVdSlVK9nPeTjxDy6%2F1%2BOxlXPUKHwyIHkHTRP5IPxd2J9%2FOx4kc2SU%2FVDmJPteCv2wU96RlLW37rgterrXauPr2srvVx2YEwkJApoel45f%2BfkX4B&RelayState=ss%3Amem%3A531967b93ad043fd65b381dc9f4dbf64562e71e1fa30a29efcad90074d7c0a1b&SAMLTRANSACTIONID=23fc9d12-a96163d2-1ebf1443-77008b54-13086b4d-ee8
So I am confused if the error I see of invalid attribute ID is actually
from shibboleth SP or SSL.
On Wed, Jun 20, 2018 at 9:13 PM Kevin Foote <kevin.foote at colorado.edu>
wrote:
>
> > On Jun 20, 2018, at 8:59 AM, Kunal Shah <ks186033 at gmail.com> wrote:
> >
> > On further research I found that this error is actually coming from
> /var/log/httpd/ssl_error_log
>
> Who’s ssl log .. yours?
>
> Your IdP metadata looks to be fine and it is registered correctly w/ the
> TS-SP.
>
>
> > [Wed Jun 20 14:28:38.091829 2018] [mod_shib:error] [pid 1251] [client
> 123.201.54.30:18945] Invalid attribute: Id, referer:
> https://cassoidp.shaku08.edu/affwebservices/public/saml2sso?SMASSERTIONREF=QUERY&SAMLRequest=fZJNU4MwFEX%2FCpN9CY1SSqYwg%2B3CzlTt2OrCjRPgVTJCgrzE6r83gB910204uTf3DAsUTd3yzJpK3cObBTTeR1Mr5MOHhNhOcS1QIleiAeSm4LvsZsOZH%2FC200YXuiZehgidkVottULbQLeD7l0W8HC%2FSUhlTIucUqxkjm0JjfaN6%2FGhtHTnznJdg6l8RE37aEa3d7s98VaOkUr0qX8ZhXCYLFsfK%2FFqg%2FkQIg6HI%2BQ4ViJtbV7LgvYDmKOJt14l5DkI4%2FhChBDnRRjF85AFBYSHQySiGYvzMHIYooW1QiOUSQgLpvNJMJuwYD%2B95Czi4fyJeNvvyVdSlVK9nPeTjxDy6%2F1%2BOxlXPUKHwyIHkHTRP5IPxd2J9%2FOx4kc2SU%2FVDmJPteCv2wU96RlLW37rgterrXauPr2srvVx2YEwkJApoel45f%2BfkX4B&RelayState=ss%3Amem%3A531967b93ad043fd65b381dc9f4dbf64562e71e1fa30a29efcad90074d7c0a1b&SAMLTRANSACTIONID=23fc9d12-a96163d2-1ebf1443-77008b54-13086b4d-ee8
> >
> > does this make sense? something to do with cert ?
>
> Apache should not be doing anything with your SAML cert(s)
>
> (The reference to mod_shib:error is a bit baffling to me)
>
> > I have converted using dos2unix and reuploaded and error persists.
>
> Again your IdP MD looks fine no dos-ish issues that I can see.
>
> I'm not sure what else we can do for you set-up wise..
>
> I am a bit confused on what you are testing though… IdP or SP both or
> something else altogether :)
>
> HTH…
>
> --------
> thanks
> kevin.foote
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180620/8be4b347/attachment.html>
More information about the users
mailing list