Hi <br><br>I am struggling to get the SP ECP binding working. Have looked at the email threads, but am not able to make out what I am doing wrong. The shibd process crashes when I send the curl command (as indicated by ecp.sh). <br>
Maybe I have misconfigured something here, but am not able to make out, any help is appreciated.<br><br>Thanks<br>Anand<br><br>Here is the last log message<br><br>2011-12-21 08:10:45 INFO Shibboleth.Listener : registered remoted message endpoint (default::getHeaders::Application)<br>
2011-12-21 08:10:45 INFO Shibboleth.Listener : listener service starting<br>2011-12-21 08:10:57 DEBUG Shibboleth.Listener [1]: dispatching message (default/Login::run::SAML2SI)<br>2011-12-21 08:10:57 DEBUG XMLTooling.StorageService [1]: inserted record (3ebec2baae691f7e09b4ef2959d5870a) in context (RelayState) with expiration (1324455657)<br>
2011-12-21 08:10:57 DEBUG OpenSAML.MessageEncoder.SAML2ECP [1]: validating input<br>2011-12-21 08:10:57 DEBUG OpenSAML.MessageEncoder.SAML2ECP [1]: marshalling the envelope<br><br>+++++++++++++++++++++++++++++++++<br>output from curl command<br>
++++++++++++++++++++++++++++++++<br><?xml version="1.0" encoding="UTF-8"?><br><!DOCTYPE html <br> PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" <br> "DTD/xhtml1-strict.dtd"><br>
<br><html xmlns="<a href="http://www.w3.org/1999/xhtml">http://www.w3.org/1999/xhtml</a>" xml:lang="en" lang="en"><br><head><br> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/><br>
<link rel="stylesheet" type="text/css" href="/shibboleth-sp/main.css" /><br> <title>shibsp&#58;&#58;ListenerException</title><br></head><br><br><body><br>
<br><img src="/shibboleth-sp/logo.jpg" alt="Logo" /><br><h1>shibsp&#58;&#58;ListenerException</h1><br><br><p>The system encountered an error at Wed Dec 21 08&#58;10&#58;57 2011<br>
</p><br><br><p>To report this problem, please contact the site administrator at<br><a href="mailto:<a href="mailto:root@localhost">root@localhost</a>">root@localhost</a>.<br></p><br>
<br><p>Please include the following message in any email:</p><br><p class="error">shibsp&#58;&#58;ListenerException at (https&#58;//<a href="http://m1234.lab.ppops.net/secure">m1234.lab.ppops.net/secure</a>)</p><br>
<br><p>Failure receiving response to remoted message &#40;default/Login&#58;&#58;run&#58;&#58;SAML2SI&#41;.</p><br><br><br>+++++++++++++++++++++++++++++++++<br>my shibboleth2.xml =><br>
+++++++++++++++++++++++++++++++++<br><ApplicationDefaults entityID="<a href="https://m1234.lab.ppops.net/shibboleth">https://m1234.lab.ppops.net/shibboleth</a>" <br> REMOTE_USER="eppn persistent-id targeted-id"><br>
<Sessions lifetime="28800" timeout="3600" checkAddress="false" relayState="ss:mem" handlerSSL="false" cookieProps="; path=/; secure"><br><br><SessionInitiator type="Chaining" Location="/Login" isDefault="true" id="Intranet" <br>
entityID="<a href="https://obelix.obelix.com/idp/shibboleth">https://obelix.obelix.com/idp/shibboleth</a>"><br> <SessionInitiator type="SAML2" ECP="true" template="bindingTemplate.html" <br>
ascIndex="3" acsByIndex="false" /><br> </SessionInitiator><br> <LogoutInitiator type="Chaining" Location="/Logout"><br> <LogoutInitiator type="Local" /><br>
</LogoutInitiator><br> <md:AssertionConsumerService Location="/SAML2/POST" index="1" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"/><br> <md:AssertionConsumerService Location="/SAML2/POST-SimpleSign" index="2" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"/><br>
<md:AssertionConsumerService Location="/SAML2/Artifact" index="3" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"/><br> <md:AssertionConsumerService Location="/SAML2/ECP" index="4" Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS"/><br>
<md:ArtifactResolutionService Location="/Artifact/SOAP" index="1" Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"/><br><Handler type="MetadataGenerator" Location="/Metadata" signing="false"/><br>
<br> <!-- Status reporting service. --><br> <Handler type="Status" Location="/Status" acl="127.0.0.1"/><br><br> <!-- Session diagnostic service. --><br>
<Handler type="Session" Location="/Session" showAttributeValues="false"/><br><br> <!-- JSON feed of discovery information. --><br> <Handler type="DiscoveryFeed" Location="/DiscoFeed"/><br>
</Sessions><br><br> <!--<br> Allows overriding of error template information/filenames. You can<br> also add attributes with values that can be plugged into the templates.<br> --><br>
<Errors supportContact="root@localhost"<br> logoLocation="/shibboleth-sp/logo.jpg"<br> styleSheet="/shibboleth-sp/main.css"/><br><br> <!-- Example of remotely supplied batch of signed metadata. --><br>
<MetadataProvider type="XML" uri="<a href="https://obelix.obelix.com/idp/profile/Metadata/SAML">https://obelix.obelix.com/idp/profile/Metadata/SAML</a>"<br> backingFilePath="federation-metadata.xml" reloadInterval="7200"><br>
<!--<br> <MetadataFilter type="RequireValidUntil" maxValidityInterval="2419200"/><br>--><br> <!--<MetadataFilter type="Signature" certificate="fedsigner.pem"/> --><br>
</MetadataProvider><br><AttributeExtractor type="XML" validate="true" path="attribute-map.xml"/><br><br> <!-- Use a SAML query if no attributes are supplied during SSO. --><br>
<AttributeResolver type="Query" subjectMatch="true"/><br><br> <!-- Default filtering policy for recognized attributes, lets other data pass. --><br> <AttributeFilter type="XML" validate="true" path="attribute-policy.xml"/><br>
<br> <!-- Simple file-based resolver for using a single keypair. --><br> <CredentialResolver type="File" key="sp-key.pem" certificate="sp-cert.pem"/><br><br> <!--<br>
The default settings can be overridden by creating ApplicationOverride elements (see<br> the <a href="https://spaces.internet2.edu/display/SHIB2/NativeSPApplicationOverride">https://spaces.internet2.edu/display/SHIB2/NativeSPApplicationOverride</a> topic).<br>
Resource requests are mapped by web server commands, or the RequestMapper, to an<br> applicationId setting.<br> <br> Example of a second application (for a second vhost) that has a different entityID.<br>
Resources on the vhost would map to an applicationId of "admin":<br> --><br> <!--<br> <ApplicationOverride id="admin" entityID="<a href="https://admin.example.org/shibboleth">https://admin.example.org/shibboleth</a>"/><br>
--><br> </ApplicationDefaults><br><br> <!-- Policies that determine how to process and authenticate runtime messages. --><br> <SecurityPolicyProvider type="XML" validate="true" path="security-policy.xml"/><br>
<br> <!-- Low-level configuration about protocols and bindings available for use. --><br> <ProtocolProvider type="XML" validate="true" reloadChanges="false" path="protocols.xml"/><br>
<br></SPConfig><br><br><br><br><br>