Thank you Nate.<div><br></div><div>Here is my log from shib.log file after getting the response message from IDP</div><div><br></div><div><div>2011-09-06 16:46:46 DEBUG OpenSAML.MessageDecoder.SAML2 [1]: extracting issuer from SAML 2.0 protocol message</div>
<div>2011-09-06 16:46:46 DEBUG OpenSAML.MessageDecoder.SAML2 [1]: message from (https://<machineA>:8443/idp/shibboleth)</div><div>2011-09-06 16:46:46 DEBUG OpenSAML.MessageDecoder.SAML2 [1]: searching metadata for message issuer...</div>
<div>2011-09-06 16:46:46 WARN OpenSAML.MessageDecoder.SAML2 [1]: no metadata found, can't establish identity of issuer (https://<machineA>:8443/idp/shibboleth)</div><div>2011-09-06 16:46:46 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [1]: evaluating message flow policy (replay checking on, expiration 60)</div>
<div>2011-09-06 16:46:46 DEBUG XMLTooling.StorageService [1]: inserted record (_7721f6220db9321bf7c363dc18537ec8) in context (MessageFlow) with expiration (1315353044)</div><div>2011-09-06 16:46:46 DEBUG OpenSAML.SecurityPolicyRule.ClientCertAuth [1]: ignoring message, no issuer metadata supplied</div>
<div>2011-09-06 16:46:46 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]: ignoring message, no issuer metadata supplied</div><div>2011-09-06 16:46:46 DEBUG OpenSAML.SecurityPolicyRule.SimpleSigning [1]: ignoring message, no issuer metadata supplied</div>
<div>2011-09-06 16:46:46 DEBUG XMLTooling.StorageService [1]: deleted record (29002348be188467e14a6c3dd62cae72) in context (RelayState)</div><div>2011-09-06 16:46:46 DEBUG Shibboleth.SSO.SAML2 [1]: processing message against SAML 2.0 SSO profile</div>
<div>2011-09-06 16:46:46 DEBUG Shibboleth.SSO.SAML2 [1]: extracting issuer from SAML 2.0 assertion</div><div>2011-09-06 16:46:46 DEBUG Shibboleth.SSO.SAML2 [1]: searching metadata for assertion issuer...</div><div>2011-09-06 16:46:46 WARN Shibboleth.SSO.SAML2 [1]: no metadata found, can't establish identity of issuer (https://<machineA>:8443/idp/shibboleth)</div>
<div>2011-09-06 16:46:46 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [1]: evaluating message flow policy (replay checking on, expiration 60)</div><div>2011-09-06 16:46:46 DEBUG XMLTooling.StorageService [1]: inserted record (_e2eac5e3db84c6bddfcc7df5483b002d) in context (MessageFlow) with expiration (1315353044)</div>
<div>2011-09-06 16:46:46 DEBUG OpenSAML.SecurityPolicyRule.ClientCertAuth [1]: ignoring message, no issuer metadata supplied</div><div>2011-09-06 16:46:46 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]: ignoring message, no issuer metadata supplied</div>
<div>2011-09-06 16:46:46 DEBUG OpenSAML.SecurityPolicyRule.SimpleSigning [1]: ignoring message, no issuer metadata supplied</div><div>2011-09-06 16:46:46 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [1]: assertion satisfied bearer confirmation requirements</div>
<div>2011-09-06 16:46:46 WARN Shibboleth.SSO.SAML2 [1]: detected a problem with assertion: Unable to establish security of incoming assertion.</div><div>2011-09-06 16:46:48 DEBUG Shibboleth.Listener [1]: dispatching message (default/SAML2/POST)</div>
<div>2011-09-06 16:46:48 DEBUG OpenSAML.MessageDecoder.SAML2POST [1]: validating input</div></div><div><br></div><div>NOTE: i can acess the IDp metadata by using URl "https://<machineA>:8443/idp/shibboleth" url. </div>
<div><br></div><div>Do we need to load the SP metadata on IDP? Is there any configuration i am missing?</div><div><br></div><div>-Pavan</div><div><br><div class="gmail_quote">On Tue, Sep 6, 2011 at 5:19 PM, Nate Klingenstein <span dir="ltr"><<a href="mailto:ndk@internet2.edu">ndk@internet2.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;"><div style="word-wrap:break-word"><div>Pavan,</div><div><br></div><div>You will need to look at your SP's shibd.log to discover the true problem, but most likely the clock on one or the other of your servers is wrong. That message is just a simpler version for browser users.</div>
<div><br></div><div>Take care,</div><div>Nate.</div><div class="im"><br><div><div>On Sep 7, 2011, at 0:06 , Pavan K wrote:</div><br><blockquote type="cite"><span style="border-collapse:separate;color:rgb(0, 0, 0);font-family:Helvetica;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;font-size:medium"><div>
And when i issue the login url "<a href="http://machineA/Shibboleth.sso/Login" target="_blank">http://machineA/Shibboleth.sso/Login</a>" user is getting authenticated on IDP and i can see the response in SP logs. Bu after that i am getting<span> </span><b>"Unable to establish security of incoming assertion".</b></div>
</span><br></blockquote></div><br></div></div><br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>