Testing new v3 IDP Issue

Mr. Christopher Bland chris at fdu.edu
Fri Feb 1 16:46:56 EST 2019


Hi All,

I recently stood up a v3.42 IDP.  I am testing by creating an entry in my /etc/hosts file for the new IDP hostname and IP address.  So far most of the SPs I visit can’t tell the difference since I am using the old v2 cert and key as the signing cert and key.  However I have a handful of SPs that are giving me the following error

opensaml::FatalProfileException at (https://sp.fdu.edu/Shibboleth.sso/SAML2/POST)

Your client's current address (X.X.X.X) differs from the one used when you authenticated to your identity provider. To correct this problem, you may need to bypass a proxy server. Please contact your local support staff or help desk for assistance.

I know that I am solely hitting the new IDP based on updates to the login page. As well as I only have my wired connect turned on. On the SPs I see

2019-02-01 16:04:09 DEBUG OpenSAML.MessageDecoder.SAML2 [198]: extracting issuer from SAML 2.0 protocol message
2019-02-01 16:04:09 DEBUG OpenSAML.MessageDecoder.SAML2 [198]: message from (https://idp.fdu.edu/idp/shibboleth)
2019-02-01 16:04:09 DEBUG OpenSAML.MessageDecoder.SAML2 [198]: searching metadata for message issuer...
2019-02-01 16:04:09 WARN Shibboleth.SSO.SAML2 [198]: detected a problem with assertion: Your client's current address (X.X.X.X) differs from the one used when you authenticated to your identity provider. To correct this problem, you may need to bypass a proxy server. Please contact your local support staff or help desk for assistance.

The problematic SPs are Shibboleth v2.5.X

Has anyone had this problem during an upgrade?

-Chris



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190201/8ffe430f/attachment.html>


More information about the users mailing list