Testing new v3 IDP Issue
Mr. Christopher Bland
chris at fdu.edu
Fri Feb 1 16:46:56 EST 2019
Hi All,
I recently stood up a v3.42 IDP. I am testing by creating an entry in my /etc/hosts file for the new IDP hostname and IP address. So far most of the SPs I visit can’t tell the difference since I am using the old v2 cert and key as the signing cert and key. However I have a handful of SPs that are giving me the following error
opensaml::FatalProfileException at (https://sp.fdu.edu/Shibboleth.sso/SAML2/POST)
Your client's current address (X.X.X.X) differs from the one used when you authenticated to your identity provider. To correct this problem, you may need to bypass a proxy server. Please contact your local support staff or help desk for assistance.
I know that I am solely hitting the new IDP based on updates to the login page. As well as I only have my wired connect turned on. On the SPs I see
2019-02-01 16:04:09 DEBUG OpenSAML.MessageDecoder.SAML2 [198]: extracting issuer from SAML 2.0 protocol message
2019-02-01 16:04:09 DEBUG OpenSAML.MessageDecoder.SAML2 [198]: message from (https://idp.fdu.edu/idp/shibboleth)
2019-02-01 16:04:09 DEBUG OpenSAML.MessageDecoder.SAML2 [198]: searching metadata for message issuer...
2019-02-01 16:04:09 WARN Shibboleth.SSO.SAML2 [198]: detected a problem with assertion: Your client's current address (X.X.X.X) differs from the one used when you authenticated to your identity provider. To correct this problem, you may need to bypass a proxy server. Please contact your local support staff or help desk for assistance.
The problematic SPs are Shibboleth v2.5.X
Has anyone had this problem during an upgrade?
-Chris
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190201/8ffe430f/attachment.html>
More information about the users
mailing list