Unknown or Unusable Identity Provider for Shib 3.2 SP

shibboleth.vse4h at simplelogin.com shibboleth.vse4h at simplelogin.com
Tue Jun 4 17:14:47 UTC 2024


Hi Peter - You said 

Did you configure the SP software with a MetadataProvider pointing to the IDP server

You'll have to forgive me since I am not the person who has configured the SP software, nor do I have direct access to it, I'm trying to provide support to the person currently managing it. I've read a little about configuration values in the MetadataProvider, I'm just not clear about the actual process for configuring these, is there an install script that's used for set-up, or can values be updated? I do manage the IdP, which was recently upgraded to simpleSAMLphp 2.x. The metadata that the IdP provides now sets an explicit entityID, where before this value was __DYNAMIC__ and automatically generated depending on the environment. Updating the entityID to use an explicit, permanent value seems to have resulted in the Shib SP errors, but again I don't have access myself to the logs on that provider. 




Sent with Proton Mail secure email.

On Monday, June 3rd, 2024 at 12:21 PM, Peter Schober via users - users at shibboleth.net <users_at_shibboleth_net_uvbvr at simplelogin.co> wrote:

> Steve Platz via users users at shibboleth.net [2024-06-03 19:05 CEST]:
> 
> > We're having issues after upgrading the SAML (php) IdP to 2.0,
> > although from everything I can tell, the Shib server is not even
> > making a request to the IdP for metadata, just returns a 500
> > /auth/shibboleth/index.php.
> 
> 
> Why would the Shibboleth SP ask the IDP for its metadata? Did you
> configure the SP software with a MetadataProvider pointing to the IDP
> server? While that's probably not a good idea security wise that can
> certainly work. The SP's log files would tell you what metadata the SP
> consumes and whether updating it from a remote URL was successful or
> not.
> 
> And who or what "returns a 500 /auth/shibboleth/index.php"? The
> webserver hosting the Shib SP software? How is that web server
> configured with regards to requests to that path?
> 
> > If we had a request to debug, this wold be easier, but I feel like
> > we need to look for some sort of misconfiguration on the SP side of
> > the equation.
> 
> 
> Log files.
> 
> HTH,
> -peter
> --
> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list