<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal>Following the instructions found here: <a href="http://www.testshib.org/testshib-two/configure.jsp">http://www.testshib.org/testshib-two/configure.jsp</a><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>I get this error trying to start shibd:<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Starting shibd: 2011-08-31 09:43:13 ERROR XMLTooling.ParserPool : error on line 12, column 51, message: no declaration found for element 'SPConfig'<o:p></o:p></p><p class=MsoNormal>2011-08-31 09:43:13 ERROR XMLTooling.ParserPool : error on line 12, column 51, message: attribute 'logger' is not declared for element 'SPConfig'<o:p></o:p></p><p class=MsoNormal>2011-08-31 09:43:13 ERROR XMLTooling.ParserPool : error on line 12, column 51, message: attribute 'clockSkew' is not declared for element 'SPConfig'<o:p></o:p></p><p class=MsoNormal>2011-08-31 09:43:13 ERROR XMLTooling.ParserPool : fatal error on line 57, column 121, message: prefix 'md' can not be resolved to namespace URI<o:p></o:p></p><p class=MsoNormal>2011-08-31 09:43:13 ERROR Shibboleth.Config : error while loading resource (/etc/shibboleth/shibboleth2.xml): XML error(s) during parsing, check log for specifics<o:p></o:p></p><p class=MsoNormal>2011-08-31 09:43:13 FATAL Shibboleth.Config : caught exception while loading configuration: XML error(s) during parsing, check log for specifics<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>I have checked my shibboleth2.xml for dingbats and I can’t find any.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Any ideas? My xml is below.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Thanks,<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Bryan<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>This is an example shibboleth2.xml generated for you by TestShib Two. It's reduced and recommented<o:p></o:p></p><p class=MsoNormal>specifically for testing. You don't need to change anything, but you may want to explore the file<o:p></o:p></p><p class=MsoNormal>to learn about how your SP works. Uncomment attributes in your attribute-map.xml file to test them.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>If you want to test advanced functionality, start from the distribution shibboleth2.xml and add the<o:p></o:p></p><p class=MsoNormal>MetadataProvider, TestShib credentials, the right entityID, and a SessionInitiator. More information:<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>https://spaces.internet2.edu/display/SHIB2/NativeSPConfiguration<o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><SPConfig logger="syslog.logger" clockSkew="1800"><o:p></o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal> You might want to increase the top-level log sensitivity in these files. <o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><OutOfProcess logger="shibd.logger"/><o:p></o:p></p><p class=MsoNormal><InProcess logger="native.logger"/><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal> Settings for session storage and internal communication. <o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><UnixListener address="shibd.sock"/><o:p></o:p></p><p class=MsoNormal><StorageService type="Memory" id="mem" cleanupInterval="900"/><o:p></o:p></p><p class=MsoNormal><SessionCache type="StorageService" StorageService="mem" cacheTimeout="3600" inprocTimeout="900" cleanupInterval="900"/><o:p></o:p></p><p class=MsoNormal><ReplayCache StorageService="mem"/><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal> The RequestMap defines portions of the webspace to protect; test-shib.acs.utah.edu/secure here. <o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><RequestMapper type="Native"><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><RequestMap applicationId="default"><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><Host name="test-shib.acs.utah.edu"><o:p></o:p></p><p class=MsoNormal><Path name="secure" authType="shibboleth" requireSession="true"/><o:p></o:p></p><p class=MsoNormal></Host><o:p></o:p></p><p class=MsoNormal></RequestMap><o:p></o:p></p><p class=MsoNormal></RequestMapper><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal> The entityID is the name TestShib made for your SP. <o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><ApplicationDefaults id="default" policyId="default" REMOTE_USER="eppn" entityID="https://test-shib.acs.utah.edu/shibboleth-sp" homeURL="https://test-shib.acs.utah.edu/index.html"><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><Sessions lifetime="28800" timeout="3600" checkAddress="false" handlerURL="/Shibboleth.sso" handlerSSL="false"><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal> SessionInitiators can request login many different ways. This example sends users directly to the<o:p></o:p></p><p class=MsoNormal> TestShib IdP. If you want to use a different IdP that has joined TestShib, just change this entityID.<o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><SessionInitiator type="SAML2" Location="/TestShib" isDefault="true" defaultACSIndex="1" id="TestShib" entityID="https://idp.testshib.org/idp/shibboleth" template="bindingTemplate.html"/><o:p></o:p></p><p class=MsoNormal><!-- How and where the SP listens. --><o:p></o:p></p><p class=MsoNormal><md:AssertionConsumerService Location="/SAML2/POST" index="1" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"/><o:p></o:p></p><p class=MsoNormal><md:AssertionConsumerService Location="/SAML/POST" index="6" Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"/><o:p></o:p></p><p class=MsoNormal><Handler type="MetadataGenerator" Location="/Metadata" signing="false"/><o:p></o:p></p><p class=MsoNormal><Handler type="Status" Location="/Status" acl="127.0.0.1"/><o:p></o:p></p><p class=MsoNormal><Handler type="Session" Location="/Session"/><o:p></o:p></p><p class=MsoNormal></Sessions><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal> Error pages to display to yourself if something goes horribly wrong. <o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><Errors session="sessionError.html" metadata="metadataError.html" access="accessError.html" ssl="sslError.html" supportContact="root@localhost" logoLocation="/shibboleth-sp/logo.jpg" styleSheet="/shibboleth-sp/main.css"/><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal> Loads and trusts a metadata file that describes only the Testshib IdP and how to communicate with it. <o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><MetadataProvider type="XML" uri="http://www.testshib.org/metadata/testshib-providers.xml" backingFilePath="testshib-two-idp-metadata.xml" reloadInterval="180000"/><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal> Attribute and trust options you shouldn't need to change. <o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><TrustEngine type="ExplicitKey"/><o:p></o:p></p><p class=MsoNormal><AttributeExtractor type="XML" path="attribute-map.xml"/><o:p></o:p></p><p class=MsoNormal><AttributeResolver type="Query"/><o:p></o:p></p><p class=MsoNormal><AttributeFilter type="XML" path="attribute-policy.xml"/><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal> Your SP generated these credentials. They're used to talk to IdP's. <o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><CredentialResolver type="File" key="sp-key.pem" certificate="sp-cert.pem"/><o:p></o:p></p><p class=MsoNormal></ApplicationDefaults><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><!--<o:p></o:p></p><p class=MsoNormal> Security policies you shouldn't change unless you know what you're doing. <o:p></o:p></p><p class=MsoNormal>--><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><SecurityPolicies><o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><Policy id="default" validate="false"><o:p></o:p></p><p class=MsoNormal><Rule type="MessageFlow" checkReplay="true" expires="60"/><o:p></o:p></p><p class=MsoNormal><Rule type="ClientCertAuth" errorFatal="true"/><o:p></o:p></p><p class=MsoNormal><Rule type="XMLSigning" errorFatal="true"/><o:p></o:p></p><p class=MsoNormal></Policy><o:p></o:p></p><p class=MsoNormal></SecurityPolicies><o:p></o:p></p><p class=MsoNormal></SPConfig><o:p></o:p></p></div></body></html>