Error using Testshib as IdP - SPSSODescriptor role metadata for entityID [REDACTED] could not be resolved

Matthew Ray Matthew.Ray at infor.com
Mon Oct 22 13:15:28 EDT 2018


Kevin, Nate:


Thanks for the advice. Maybe the term "health check" was misleading; this is not an automated poll. We use local logins for most of our QA testing and dev work, but from time to time QA tests the SSO feature by hand. But I will talk to my team lead about setting up a local IdP. In the interim, SAMLTest.id looks like our best bet.


Matthew

________________________________
From: users <users-bounces at shibboleth.net> on behalf of Nate Klingenstein <ndk at signet.id>
Sent: Monday, October 22, 2018 1:03:07 PM
To: Shib Users
Subject: RE: Error using Testshib as IdP - SPSSODescriptor role metadata for entityID [REDACTED] could not be resolved

Sent by an external sender
------------------------------------


I agree with virtually Kevin said, but I wouldn't personally find a sanity check against SAMLtest every week or so to be a bad thing or too much load, and now that metadata should be persistent, it might be something we could consider.  That said, Kevin's point about an internal IdP is spot on.



We did have a deployer who had a health check that polled TestShib every 2 seconds for awhile.  They were very gracious in stopping and repenting.



-----Original message-----
From: Kevin Foote
Sent: Monday, October 22 2018, 10:55 am
To: Shib Users
Subject: Re: Error using Testshib as IdP - SPSSODescriptor role metadata for entityID [REDACTED] could not be resolved


Hi Matthew,

> On Oct 22, 2018, at 10:43 AM, Matthew Ray <Matthew.Ray at infor.com<mailto:Matthew.Ray at infor.com>> wrote:
>
> We have a number of test environments that use Testshib for an IdP as a kind of sanity check, just to make sure that our SSO functionality isn't completely broken.

For starters your not supposed to do that .. It (testshib) was never designed for that type of use. Using something out of your control for a  health-check is a bad idea regardless of the external design.

> Could anyone explain what is happening?

Next .. we have kind of abandoned that [1] service.
Use the next generation configuration for a simple one time check (NOT a health-check).


[1] https://marc.info/?l=shibboleth-users&m=153856905122908&w=2


--------
thanks
 kevin.foote
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181022/2bc77321/attachment.html>


More information about the users mailing list