<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal>Following the instructions found here: <a href="http://www.testshib.org/testshib-two/configure.jsp">http://www.testshib.org/testshib-two/configure.jsp</a><o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>I get this error trying to start shibd:<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Starting shibd: 2011-08-31 09:43:13 ERROR XMLTooling.ParserPool : error on line 12, column 51, message: no declaration found for element 'SPConfig'<o:p></o:p></p><p class=MsoNormal>2011-08-31 09:43:13 ERROR XMLTooling.ParserPool : error on line 12, column 51, message: attribute 'logger' is not declared for element 'SPConfig'<o:p></o:p></p><p class=MsoNormal>2011-08-31 09:43:13 ERROR XMLTooling.ParserPool : error on line 12, column 51, message: attribute 'clockSkew' is not declared for element 'SPConfig'<o:p></o:p></p><p class=MsoNormal>2011-08-31 09:43:13 ERROR XMLTooling.ParserPool : fatal error on line 57, column 121, message: prefix 'md' can not be resolved to namespace URI<o:p></o:p></p><p class=MsoNormal>2011-08-31 09:43:13 ERROR Shibboleth.Config : error while loading resource (/etc/shibboleth/shibboleth2.xml): XML error(s) during parsing, check log for specifics<o:p></o:p></p><p class=MsoNormal>2011-08-31 09:43:13 FATAL Shibboleth.Config : caught exception while loading configuration: XML error(s) during parsing, check log for specifics<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>I have checked my shibboleth2.xml for dingbats and I can&#8217;t find any.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Any ideas? My xml is below.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Thanks,<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Bryan<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>This is an example shibboleth2.xml generated for you by TestShib Two.&nbsp; It's reduced and recommented<o:p></o:p></p><p class=MsoNormal>specifically for testing.&nbsp; You don't need to change anything, but you may want to explore the file<o:p></o:p></p><p class=MsoNormal>to learn about how your SP works.&nbsp; Uncomment attributes in your attribute-map.xml file to test them.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>If you want to test advanced functionality, start from the distribution shibboleth2.xml and add the<o:p></o:p></p><p class=MsoNormal>MetadataProvider, TestShib credentials, the right entityID, and a SessionInitiator.&nbsp; More information:<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>https://spaces.internet2.edu/display/SHIB2/NativeSPConfiguration<o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal>&lt;SPConfig logger=&quot;syslog.logger&quot; clockSkew=&quot;1800&quot;&gt;<o:p></o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal> You might want to increase the top-level log sensitivity in these files. <o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal>&lt;OutOfProcess logger=&quot;shibd.logger&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;InProcess logger=&quot;native.logger&quot;/&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal> Settings for session storage and internal communication. <o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal>&lt;UnixListener address=&quot;shibd.sock&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;StorageService type=&quot;Memory&quot; id=&quot;mem&quot; cleanupInterval=&quot;900&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;SessionCache type=&quot;StorageService&quot; StorageService=&quot;mem&quot; cacheTimeout=&quot;3600&quot; inprocTimeout=&quot;900&quot; cleanupInterval=&quot;900&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;ReplayCache StorageService=&quot;mem&quot;/&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal> The RequestMap defines portions of the webspace to protect; test-shib.acs.utah.edu/secure here. <o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;RequestMapper type=&quot;Native&quot;&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;RequestMap applicationId=&quot;default&quot;&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;Host name=&quot;test-shib.acs.utah.edu&quot;&gt;<o:p></o:p></p><p class=MsoNormal>&lt;Path name=&quot;secure&quot; authType=&quot;shibboleth&quot; requireSession=&quot;true&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;/Host&gt;<o:p></o:p></p><p class=MsoNormal>&lt;/RequestMap&gt;<o:p></o:p></p><p class=MsoNormal>&lt;/RequestMapper&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal> The entityID is the name TestShib made for your SP. <o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;ApplicationDefaults id=&quot;default&quot; policyId=&quot;default&quot; REMOTE_USER=&quot;eppn&quot; entityID=&quot;https://test-shib.acs.utah.edu/shibboleth-sp&quot; homeURL=&quot;https://test-shib.acs.utah.edu/index.html&quot;&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;Sessions lifetime=&quot;28800&quot; timeout=&quot;3600&quot; checkAddress=&quot;false&quot; handlerURL=&quot;/Shibboleth.sso&quot; handlerSSL=&quot;false&quot;&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; SessionInitiators can request login many different ways.&nbsp; This example sends users directly to the<o:p></o:p></p><p class=MsoNormal>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TestShib IdP.&nbsp; If you want to use a different IdP that has joined TestShib, just change this entityID.<o:p></o:p></p><p class=MsoNormal>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal>&lt;SessionInitiator type=&quot;SAML2&quot; Location=&quot;/TestShib&quot; isDefault=&quot;true&quot; defaultACSIndex=&quot;1&quot; id=&quot;TestShib&quot; entityID=&quot;https://idp.testshib.org/idp/shibboleth&quot; template=&quot;bindingTemplate.html&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;!-- How and where the SP listens. --&gt;<o:p></o:p></p><p class=MsoNormal>&lt;md:AssertionConsumerService Location=&quot;/SAML2/POST&quot; index=&quot;1&quot; Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;md:AssertionConsumerService Location=&quot;/SAML/POST&quot; index=&quot;6&quot; Binding=&quot;urn:oasis:names:tc:SAML:1.0:profiles:browser-post&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;Handler type=&quot;MetadataGenerator&quot; Location=&quot;/Metadata&quot; signing=&quot;false&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;Handler type=&quot;Status&quot; Location=&quot;/Status&quot; acl=&quot;127.0.0.1&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;Handler type=&quot;Session&quot; Location=&quot;/Session&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;/Sessions&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal> Error pages to display to yourself if something goes horribly wrong. <o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal>&lt;Errors session=&quot;sessionError.html&quot; metadata=&quot;metadataError.html&quot; access=&quot;accessError.html&quot; ssl=&quot;sslError.html&quot; supportContact=&quot;root@localhost&quot; logoLocation=&quot;/shibboleth-sp/logo.jpg&quot; styleSheet=&quot;/shibboleth-sp/main.css&quot;/&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal> Loads and trusts a metadata file that describes only the Testshib IdP and how to communicate with it. <o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal>&lt;MetadataProvider type=&quot;XML&quot; uri=&quot;http://www.testshib.org/metadata/testshib-providers.xml&quot; backingFilePath=&quot;testshib-two-idp-metadata.xml&quot; reloadInterval=&quot;180000&quot;/&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal> Attribute and trust options you shouldn't need to change. <o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal>&lt;TrustEngine type=&quot;ExplicitKey&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;AttributeExtractor type=&quot;XML&quot; path=&quot;attribute-map.xml&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;AttributeResolver type=&quot;Query&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;AttributeFilter type=&quot;XML&quot; path=&quot;attribute-policy.xml&quot;/&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal> Your SP generated these credentials.&nbsp; They're used to talk to IdP's. <o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal>&lt;CredentialResolver type=&quot;File&quot; key=&quot;sp-key.pem&quot; certificate=&quot;sp-cert.pem&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;/ApplicationDefaults&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;!--<o:p></o:p></p><p class=MsoNormal> Security policies you shouldn't change unless you know what you're doing. <o:p></o:p></p><p class=MsoNormal>--&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;SecurityPolicies&gt;<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>&lt;Policy id=&quot;default&quot; validate=&quot;false&quot;&gt;<o:p></o:p></p><p class=MsoNormal>&lt;Rule type=&quot;MessageFlow&quot; checkReplay=&quot;true&quot; expires=&quot;60&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;Rule type=&quot;ClientCertAuth&quot; errorFatal=&quot;true&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;Rule type=&quot;XMLSigning&quot; errorFatal=&quot;true&quot;/&gt;<o:p></o:p></p><p class=MsoNormal>&lt;/Policy&gt;<o:p></o:p></p><p class=MsoNormal>&lt;/SecurityPolicies&gt;<o:p></o:p></p><p class=MsoNormal>&lt;/SPConfig&gt;<o:p></o:p></p></div></body></html>