Unknown or Unusable Identity Provider for Shib 3.2 SP
shibboleth.vse4h at simplelogin.com
shibboleth.vse4h at simplelogin.com
Tue Jun 4 18:27:35 UTC 2024
The person managing the SP would like to set the entityID to the historical autogenerated value, and I think that's fine to test, but unfortunately the autogenerated value would make an ill-formed entityID if we used it permanently, since it ends with metadata.php and begins with the URI for a development instance etc. Can't we update the shibboleth2.xml with a new entityID?
Sent with Proton Mail secure email.
On Tuesday, June 4th, 2024 at 11:12 AM, Peter Schober via users - users at shibboleth.net <users_at_shibboleth_net_uvbvr at simplelogin.co> wrote:
> Steve Platz via users users at shibboleth.net [2024-06-04 19:15 CEST]:
>
> > You'll have to forgive me since I am not the person who has
> > configured the SP software, nor do I have direct access to it, I'm
> > trying to provide support to the person currently managing it.
>
>
> If the only change was the one on the IDP-side you mentioned then you
> might get away without any access nor knowledge about the SP.
>
> Note that SP version 3.2 is not current and no longer supported by the
> Shibboleth project, https://shibboleth.atlassian.net/wiki/spaces/SP3/
>
> > I do manage the IdP, which was recently upgraded to simpleSAMLphp
> > 2.x. The metadata that the IdP provides now sets an explicit
> > entityID, where before this value was DYNAMIC and automatically
> > generated depending on the environment. Updating the entityID to use
> > an explicit, permanent value seems to have resulted in the Shib SP
> > errors, but again I don't have access myself to the logs on that
> > provider.
>
>
> Well, the first thing to do on the IDP side then is to explicitly set
> the entityID to the exact same value that was autogenerated before.
> (You can probably still see this in the metadata about the IDP you
> gave to other SPs.)
> I would expect that to take care of the "unknown IDP" error.
>
> -peter
> --
> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list