<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">I have a school that is a member of InCommon but have spun up a new Idp that is not part of InCommon.</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif"><br></font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">So I set them up as a private federation (I have setup lots of these before with no issues) by adding the following session initiator config:</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif"><br></font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SessionInitiator type="Chaining" Location="/Login" isDefault="true" id="Intranet" relayState="cookie"
 entityID="https://idp2.unr.edu/idp/shibboleth"&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SessionInitiator type="SAML2" acsIndex="1" acsByIndex="false" template="bindingTemplate.html"/&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SessionInitiator type="Shib1" acsIndex="5"/&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/SessionInitiator&gt;<span class="Apple-tab-span" style="white-space:pre">        </span></font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif"><br></font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">And metadata:</font></div><div><font class="Apple-style-span" face="arial, helvetica,
 sans-serif"><br></font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif"><span class="Apple-tab-span" style="white-space:pre">                </span>&lt;MetadataProvider type="XML" uri="https://cas.masdar.ac.ae/idp/profile/Metadata/SAML" /&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif"><br></font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">When they attempt to authenticate to me, a redirect back to their site occurs for username/pass challenge. &nbsp;Upon sign in, they redirect back to me with this assertion:</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif"><br></font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&lt;?xml version="1.0" encoding="UTF-8"?&gt;&lt;saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_25001fe90a27cf014fd8c8627a5915f4"
 IssueInstant="2012-10-02T18:32:41.984Z" Version="2.0" xmlns:xs="http://www.w3.org/2001/XMLSchema"&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"&gt;https://idp2.unr.edu/idp/shibboleth&lt;/saml2:Issuer&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;ds:SignedInfo&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp;
 &nbsp;&lt;ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;ds:Reference URI="#_25001fe90a27cf014fd8c8627a5915f4"&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:Transforms&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp;
 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ec:InclusiveNamespaces xmlns:ec="http://www.w3.org/2001/10/xml-exc-c14n#" PrefixList="xs"/&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;/ds:Transform&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/ds:Transforms&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:DigestValue&gt;6wzppl9E+qGg9H8LjCdEr8wG4Qg=&lt;/ds:DigestValue&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp;
 &nbsp;&lt;/ds:Reference&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;/ds:SignedInfo&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;ds:SignatureValue&gt;e1v32pRcuykzLQ+0Vifc65pjf1PS/jAniU8onUmVOi7+tzx6B/lpwZzrAR59xLI+9pZHrGCjpLHOgUsKQynoKg1uAxymB91+Z0aqkUN1DpPCqBoeOMrwbwT4iHHoq1q0WBbIxX1/bdd7QRi7QsVs1mwpPvQiJDkxOAIyOg5s9kjw4MeUkcCIR3rzE54PFmX2u2Y4Gsi6ZOirriTufvKLh+6gFzsTLaUjjkLy5KSLz5Ihv3Z92Ch+joXMNo0YgUA/Dg/h+vIRBZ6ePdhRoG3Kp6gYOGr14G0yD02ngcCMrWsLVsY5b5rwS8rrcw5p7JvjCQltb8CyKzW57PqbLC+wPQ==&lt;/ds:SignatureValue&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;ds:KeyInfo&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;ds:X509Data&gt;</font></div><div><font class="Apple-style-span"
 face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:X509Certificate&gt;MIIDIzCCAgugAwIBAgIJAKe3lmdIL/y1MA0GCSqGSIb3DQEBBQUAMBUxEzARBgNVBAMTCmFhLnVu</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">ci5lZHUwHhcNMTAxMDIxMTczNjQ4WhcNMTMxMDIwMTczNjQ4WjAVMRMwEQYDVQQDEwphYS51bnIu</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">ZWR1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyjOvGetymBixa0PMEgvFp7GqUp+Y</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">rdF0RRgTfAFv9RwuysFMYDlqMjcrsqrmQnQrhs3OEkJj90BZN3d8rt03aVo3fy+o3gxswMkjGzF5</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">cNFCVvUXKQj23pEJI5LuqCQD/QTE+uql5+V/nScwZBRs1SIp3795pDp/wY6xj97/zB63n6Z0wyf9</font></div><div><font class="Apple-style-span" face="arial, helvetica,
 sans-serif">OWFCEZPFk85TatyMFr/uSXnklIWOjCkTtmR5hI6NJG7jolAugSewjuWEsyeYAVVz027Va6JhIe9s</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">G0huQsayBrZU7dckbJaLuw2yLa6BMcW/OuA6gvsVQy/t0eDXcg7nzxycTOFl7AQDME31WdUwNpBP</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">/WnD6n2CPQIDAQABo3YwdDAdBgNVHQ4EFgQUjwfbzOjd6U1d8h/FnUknbgVVsa8wRQYDVR0jBD4w</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">PIAUjwfbzOjd6U1d8h/FnUknbgVVsa+hGaQXMBUxEzARBgNVBAMTCmFhLnVuci5lZHWCCQCnt5Zn</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">SC/8tTAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4IBAQBkyQVyw/QN/yxR6X0YP7I2F05c</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">5tg2fLcfVRaei6aT0LamyiSioHESyPAwHY8QnC0HRC3lAsS8Gj6F4f4Cr9S0YnUe4lICqVRwjki9</font></div><div><font class="Apple-style-span" face="arial, helvetica,
 sans-serif">mzsD/ROpDusKraFy72K4WxKvT4S10g67KUZcskG6IKLxhr0vJ5s3TO7pX9C4MMUian2WLFX+ZbaQ</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">rcc1b0OgqrBXYoBu4CBu8UyI+87Yk92kT6ffKNWTaB19lq/B8bSrzr9PF9LlGOMP1B9ybDXZF6LQ</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">MoLe2sRYfZHN4YO8atYKriQulEdKJcwie411IeKKNcTderZ024iKboHzbIxRndJ4m65mN+WzrvPC</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">fCzkE/bHaNBR&lt;/ds:X509Certificate&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;/ds:X509Data&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;/ds:KeyInfo&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;/ds:Signature&gt;</font></div><div><font class="Apple-style-span"
 face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;saml2:Subject&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;saml2:SubjectConfirmationData Address="134.197.86.126" InResponseTo="_d6580db7cff14d7bdbd704d600d37f9d" NotOnOrAfter="2012-10-02T18:37:41.984Z" Recipient="https://shib.lynda.com/Shibboleth.sso/SAML2/POST"/&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;/saml2:SubjectConfirmation&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;/saml2:Subject&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;saml2:Conditions
 NotBefore="2012-10-02T18:32:41.984Z" NotOnOrAfter="2012-10-02T18:37:41.984Z"&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;saml2:AudienceRestriction&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;saml2:Audience&gt;https://shib.lynda.com/shibboleth-sp&lt;/saml2:Audience&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;/saml2:AudienceRestriction&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;/saml2:Conditions&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;saml2:AuthnStatement AuthnInstant="2012-10-02T18:32:41.107Z" SessionIndex="f6c1090b6a76c2e2c45bbcb5cc8154ddab62022f038a3e78cf7c04cbdb42cf3c"&gt;</font></div><div><font
 class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;saml2:SubjectLocality Address="134.197.86.126"/&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;saml2:AuthnContext&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;saml2:AuthnContextClassRef&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport&lt;/saml2:AuthnContextClassRef&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;/saml2:AuthnContext&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;/saml2:AuthnStatement&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;saml2:AttributeStatement&gt;</font></div><div><font class="Apple-style-span"
 face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;saml2:AttributeValue xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string"&gt;Hegie&lt;/saml2:AttributeValue&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;/saml2:Attribute&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;saml2:AttributeValue
 xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:type="xs:string"&gt;Joshua&lt;/saml2:AttributeValue&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;/saml2:Attribute&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;saml2:Attribute FriendlyName="eduPersonTargetedID" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;saml2:AttributeValue&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="https://idp2.unr.edu/idp/shibboleth"
 SPNameQualifier="https://shib.lynda.com/shibboleth-sp"&gt;ifE+PletjKeZsX7BpH/wn2lsprQ=&lt;/saml2:NameID&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;/saml2:AttributeValue&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp; &nbsp; &lt;/saml2:Attribute&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&nbsp; &nbsp;&lt;/saml2:AttributeStatement&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">&lt;/saml2:Assertion&gt;</font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif"><br></font></div><div><font class="Apple-style-span" face="arial, helvetica, sans-serif">They are getting a 500 error. &nbsp;There is nothing in the logs for it (no suprise since it's a 500). Yes, they are passing eduPersonTargetedID as their security
 policy precludes the release of EPPN (that I would normally expect). &nbsp;I have asked them to change this to persistant-id but I doubt that is the issue here regardless. &nbsp; Can anyone provide some guidance as to how to debug this? &nbsp;</font></div><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt; "><br></div></div></div></body></html>