<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Thank you Chad, you are correct. I had missed that there is a separate default ServerName for 443 in httpd-ssl.conf. Dang.<div><br></div><div>But now it works! :)</div><div><div><div>
<span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><div><span class="Apple-style-span" style="color: rgb(51, 153, 153); font-family: 'Lucida Grande'; font-size: 11px; line-height: 13px; "><strong style="color: rgb(51, 153, 153); "><br class="Apple-interchange-newline">Per Ejeklint</strong></span></div><div><span class="Apple-style-span" style="color: rgb(51, 153, 153); font-family: 'Lucida Grande'; font-size: 11px; line-height: 13px; "><strong style="color: rgb(51, 153, 153); "></strong></span><span class="Apple-style-span" style="color: rgb(51, 153, 153); font-family: 'Lucida Grande'; font-size: 11px; line-height: 13px; ">Address:&nbsp;<a href="http://www.heimore.com/" title="visit heimore.com" style="color: rgb(51, 153, 153); text-decoration: none; border-bottom-width: 1px; border-bottom-color: rgb(153, 153, 153); border-bottom-style: dotted; ">Heimore Group AB</a></span><span class="Apple-style-span" style="color: rgb(51, 153, 153); font-family: 'Lucida Grande'; font-size: 11px; line-height: 13px; ">, Götgatan 78 22th floor, SE-118 30&nbsp;</span><span class="Apple-style-span" style="color: rgb(51, 153, 153); font-family: 'Lucida Grande'; font-size: 11px; line-height: 13px; "><a href="http://www.stockholm.se/" title="visit Stockholm" style="color: rgb(51, 153, 153); text-decoration: none; border-bottom-width: 1px; border-bottom-color: rgb(153, 153, 153); border-bottom-style: dotted; ">Stockholm</a></span><span class="Apple-style-span" style="color: rgb(51, 153, 153); font-family: 'Lucida Grande'; font-size: 11px; line-height: 13px; ">,&nbsp;</span><span class="Apple-style-span" style="color: rgb(51, 153, 153); font-family: 'Lucida Grande'; font-size: 11px; line-height: 13px; "><a href="http://www.sweden.se/" title="visit Sweden" style="color: rgb(51, 153, 153); text-decoration: none; border-bottom-width: 1px; border-bottom-color: rgb(153, 153, 153); border-bottom-style: dotted; ">Sweden</a></span><span class="Apple-style-span" style="color: rgb(51, 153, 153); font-family: 'Lucida Grande'; font-size: 11px; line-height: 13px; "><br></span><span class="Apple-style-span" style="color: rgb(51, 153, 153); font-family: 'Lucida Grande'; font-size: 11px; line-height: 13px; ">Phone: +4670-5090052</span></div></div></div></span><br class="Apple-interchange-newline"></span><br class="Apple-interchange-newline">
</div>
<br><div><div>4 maj 2012 kl. 15:19 skrev Chad La Joie:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div>What is occurring is the SP is sending an authn request that contains<br>the <a href="http://example.com">example.com</a> hostname. &nbsp;The IdP then checks its metadata (which is<br>viewed as trusted, authoritative information about relying parties to<br>which it communicates) to ensure that the URL given in the request<br>matches the URL in the metadata and that's failing. &nbsp;So it's not the<br>IdP pulling that incorrect URL from metadata, it's the SP giving it to<br>the IdP and the IdP noticing a mismatch from what its supposed to be.<br><br>So, the issue is a SP-environment issues. &nbsp;Specifically, your<br>webserver is probably misconfigured and telling the SP that the<br>hostname of the server is <a href="http://example.com">example.com</a> at the time that SP is<br>constructing that ACS URL.<br><br>On Fri, May 4, 2012 at 9:10 AM, Per Ejeklint &lt;<a href="mailto:per.ejeklint@heimore.com">per.ejeklint@heimore.com</a>&gt; wrote:<br><blockquote type="cite">Hey world, new Shibboleth user here!<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">I'm trying to set up a local installation of IdP and SP on the same machine<br></blockquote><blockquote type="cite">(Mac OS X Lion) and have gotten it to work - almost. I stumble upon a<br></blockquote><blockquote type="cite">mismatch in URLs after successfully have logged in with the configured LDAP.<br></blockquote><blockquote type="cite">IDP says<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">WARN [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] -<br></blockquote><blockquote type="cite">Relying party '<a href="https://sp.ejeklint.se/shibboleth'">https://sp.ejeklint.se/shibboleth'</a> requested the response to<br></blockquote><blockquote type="cite">be returned to endpoint with ACS URL<br></blockquote><blockquote type="cite">'<a href="https://www.example.com/Shibboleth.sso/SAML2/POST'">https://www.example.com/Shibboleth.sso/SAML2/POST'</a> &nbsp;and binding<br></blockquote><blockquote type="cite">'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however no endpoint, with<br></blockquote><blockquote type="cite">that URL and using a supported binding, &nbsp;can be found in the relying party's<br></blockquote><blockquote type="cite">metadata<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">and that's fair enough as "<a href="https://www.example.com">https://www.example.com</a>..." is not a correct URL.<br></blockquote><blockquote type="cite">But the thing is that I share metadata ONLY through files, and in my<br></blockquote><blockquote type="cite">metadata file for the SP there is not a trace left of "<a href="http://www.example.com">www.example.com</a>" - my<br></blockquote><blockquote type="cite">own machine name is there.<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">For some reason the IdP seem to pick the ACS URL from the running SP and not<br></blockquote><blockquote type="cite">from the metadata file I have provided. Now I'm stuck and need a (gentle)<br></blockquote><blockquote type="cite">kick in the right direction.<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Here's my metadata tags in RelyingParty.xml:<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &lt;!-- ========================================== --&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &lt;!-- &nbsp; &nbsp; &nbsp;Metadata Configuration &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;--&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &lt;!-- ========================================== --&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &lt;!-- MetadataProvider the combining other MetadataProviders --&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &lt;metadata:MetadataProvider id="ShibbolethMetadata"<br></blockquote><blockquote type="cite">xsi:type="metadata:ChainingMetadataProvider"&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &lt;!-- Load the IdP's own metadata. &nbsp;This is necessary for artifact<br></blockquote><blockquote type="cite">support. --&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;metadata:MetadataProvider id="IdPMD"<br></blockquote><blockquote type="cite">xsi:type="metadata:ResourceBackedMetadataProvider"&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;metadata:MetadataResource<br></blockquote><blockquote type="cite">xsi:type="resource:FilesystemResource"<br></blockquote><blockquote type="cite">file="/opt/shibboleth-idp/metadata/idp-metadata.xml"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;/metadata:MetadataProvider&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Load the SP's metadata. &nbsp;--&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;metadata:MetadataProvider xsi:type="FilesystemMetadataProvider"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; xmlns="urn:mace:shibboleth:2.0:metadata" id="SPMETADATA"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; metadataFile="/opt/shibboleth-idp/metadata/sp-metadata.xml" /&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &lt;/metadata:MetadataProvider&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">And here is the sp-metadata.xml that is referred to from RelyingParty.xml:<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp;&lt;EntityDescriptor entityID="<a href="https://sp.ejeklint.se/shibboleth">https://sp.ejeklint.se/shibboleth</a>"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- The TestShib Two SP supports SAML 2.0, SAML 1.1, and Shibboleth<br></blockquote><blockquote type="cite">1.2+. --&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;SPSSODescriptor<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol<br></blockquote><blockquote type="cite">urn:oasis:names:tc:SAML:1.1:protocol"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Extensions xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Extension to permit the SP to receive IdP discovery<br></blockquote><blockquote type="cite">responses. --&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;idpdisc:DiscoveryResponse<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/Login">https://sp.ejeklint.se/Shibboleth.sso/Login</a>"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; index="1"<br></blockquote><blockquote type="cite">xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;idpdisc:DiscoveryResponse<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/Login">https://sp.ejeklint.se/Shibboleth.sso/Login</a>"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; index="2"<br></blockquote><blockquote type="cite">xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/Extensions&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">[verbose key stuff removed...]<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- This tells IdPs that Single Logout is supported and<br></blockquote><blockquote type="cite">where/how to request it. --&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SingleLogoutService<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/SLO/SOAP">https://sp.ejeklint.se/Shibboleth.sso/SLO/SOAP</a>"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SingleLogoutService<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/SLO/Redirect">https://sp.ejeklint.se/Shibboleth.sso/SLO/Redirect</a>"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SingleLogoutService<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/SLO/POST">https://sp.ejeklint.se/Shibboleth.sso/SLO/POST</a>"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SingleLogoutService<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/SLO/Artifact">https://sp.ejeklint.se/Shibboleth.sso/SLO/Artifact</a>"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- This tells IdPs that you only need transient identifiers.<br></blockquote><blockquote type="cite">--&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;NameIDFormat<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&lt;/NameIDFormat&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;NameIDFormat<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;urn:mace:shibboleth:1.0:nameIdentifier&lt;/NameIDFormat&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!--<br></blockquote><blockquote type="cite">This tells IdPs where and how to push assertions through the browser. Mostly<br></blockquote><blockquote type="cite">the SP will tell the IdP what location to use in its request, but this<br></blockquote><blockquote type="cite">is how the IdP validates the location and also figures out which<br></blockquote><blockquote type="cite">SAML version/binding to use.<br></blockquote><blockquote type="cite">--&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;AssertionConsumerService<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/SAML2/POST">https://sp.ejeklint.se/Shibboleth.sso/SAML2/POST</a>"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; index="1" isDefault="true"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;AssertionConsumerService<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/SAML2/POST-SimpleSign">https://sp.ejeklint.se/Shibboleth.sso/SAML2/POST-SimpleSign</a>"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; index="2" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;AssertionConsumerService<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/SAML2/Artifact">https://sp.ejeklint.se/Shibboleth.sso/SAML2/Artifact</a>"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; index="3" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;AssertionConsumerService<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/SAML/POST">https://sp.ejeklint.se/Shibboleth.sso/SAML/POST</a>"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; index="4" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;AssertionConsumerService<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Location="<a href="https://sp.ejeklint.se/Shibboleth.sso/SAML/Artifact">https://sp.ejeklint.se/Shibboleth.sso/SAML/Artifact</a>"<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; index="5" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"/&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &lt;!--<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp;&lt;AttributeConsumingService index="1"&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;ServiceName xml:lang="en"&gt;secure&lt;/ServiceName&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp;&lt;ServiceDescription xml:lang="en"&gt;An example service that requires a<br></blockquote><blockquote type="cite">human-readable identifier and optional name and e-mail<br></blockquote><blockquote type="cite">address.&lt;/ServiceDescription&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp;&lt;/AttributeConsumingService&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp;--&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp;&lt;/SPSSODescriptor&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- This is just information about the entity in human terms. --&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;Organization xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;OrganizationName xml:lang="en"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;Shibboleth SP at<br></blockquote><blockquote type="cite"><a href="http://ejeklint.se">ejeklint.se</a>&lt;/OrganizationName&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;OrganizationDisplayName xml:lang="en"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;EE SP&lt;/OrganizationDisplayName&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;OrganizationURL xml:lang="en"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;<a href="http://www.ejeklint.se&lt;/OrganizationURL&gt;">http://www.ejeklint.se&lt;/OrganizationURL&gt;</a><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;/Organization&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;ContactPerson contactType="technical"<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;GivenName<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;Per&lt;/GivenName&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SurName<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;Ejeklint&lt;/SurName&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;EmailAddress<br></blockquote><blockquote type="cite">xmlns="urn:oasis:names:tc:SAML:2.0:metadata"&gt;mailto:ejeklint@me.com&lt;/EmailAddress&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;/ContactPerson&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &lt;/EntityDescriptor&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">As for the configuration of the SP, there is indeed a problem with the<br></blockquote><blockquote type="cite">RequestMapper (I think). The metadata that is available<br></blockquote><blockquote type="cite">from&nbsp;<a href="https://sp.ejeklint.se/Shibboleth.sso/Metadata">https://sp.ejeklint.se/Shibboleth.sso/Metadata</a> does indeed have the<br></blockquote><blockquote type="cite">wrong URLs with <a href="http://www.example.com">www.example.com</a> in them, but as I don't have a metadata<br></blockquote><blockquote type="cite">provider pointing to that URL it should still work. Or am I ignorant about<br></blockquote><blockquote type="cite">something here? This is the RequestMapper in shibboleth2.xml which isn't<br></blockquote><blockquote type="cite">doing what I expect:<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &lt;RequestMapper type="Native"&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;RequestMap&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!--<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; The example requires a session for documents in /secure on the<br></blockquote><blockquote type="cite">containing host with http and<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; https on the default ports. Note that the name and port in the<br></blockquote><blockquote type="cite">&lt;Host&gt; elements MUST match<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Apache's ServerName and Port directives or the IIS Site name in<br></blockquote><blockquote type="cite">the &lt;ISAPI&gt; element above.<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; --&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Host name="<a href="http://sp.ejeklint.se">sp.ejeklint.se</a>"&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Path name="secure" authType="shibboleth"<br></blockquote><blockquote type="cite">requireSession="true"/&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/Host&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">&nbsp; &nbsp; &nbsp; &nbsp; &lt;/RequestMap&gt;<br></blockquote><blockquote type="cite">&nbsp; &nbsp; &lt;/RequestMapper&gt;<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Any ideas?<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">Per Ejeklint<br></blockquote><blockquote type="cite">Address:&nbsp;Heimore Group AB, Götgatan 78 22th floor, SE-118<br></blockquote><blockquote type="cite">30&nbsp;Stockholm,&nbsp;Sweden<br></blockquote><blockquote type="cite">Phone: +4670-5090052<br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite"><br></blockquote><blockquote type="cite">--<br></blockquote><blockquote type="cite">To unsubscribe from this list send an email to<br></blockquote><blockquote type="cite"><a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote><br><br><br>-- <br>Chad La Joie<br><a href="http://www.itumi.biz">www.itumi.biz</a><br>trusted identities, delivered<br>--<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br></div></blockquote></div><br></div></div></body></html>