<html><head><meta http-equiv="Content-Type" content="text/html charset=iso-8859-1"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div><div>On Oct 12, 2012, at 3:40 PM, Ryan Suarez &lt;<a href="mailto:ryan.suarez@sheridanc.on.ca">ryan.suarez@sheridanc.on.ca</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">
  
    <meta content="text/html; charset=ISO-8859-1" http-equiv="Content-Type">
  
  <div bgcolor="#FFFFFF" text="#000000">
    <div class="moz-cite-prefix">On 12-10-11 9:27 AM, Joost van Dijk
      wrote:<br>
    </div>
    <blockquote cite="mid:96528DB0-C76A-45E4-96A9-E249875FA789@surfnet.nl" type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <base href="x-msg://4805/">
      <div>Not sure if you already resolved your issues, but I believe
        that the message in your log file:</div>
      <div><br>
      </div>
      <div><span style="font-family: Calibri, sans-serif; font-size:
          15px; ">No return endpoint available for relying party</span><span class="apple-converted-space" style="font-family: Calibri,
          sans-serif; font-size: 15px; ">&nbsp;</span><a moz-do-not-send="true" href="urn:federation:MicrosoftOnline" style="color: purple; font-family: Calibri, sans-serif;
          font-size: 15px; ">urn:federation:MicrosoftOnline</a></div>
      <div><br>
      </div>
      <div>has nothing to do with your setup but is related to an issue
        with Office 365.</div>
      <div>When a user connects to Microsoft's IMAP server, for example,
        he/she sends a username and password for authentication that is
        subsequently relayed to the user's IdP using the SAML ECP
        profile. That is, a SOAP request is sent from Microsoft's
        servers to your IdP's ECP endpoint (using HTTP Basic
        authentication), e.g.</div>
      <div><br>
      </div>
      <div>
        <div>&lt;S:Envelope xmlns:S="<a moz-do-not-send="true" href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>"&gt;</div>
        <div>&nbsp; &lt;S:Body&gt;</div>
        <div>&nbsp; &nbsp; &lt;samlp:AuthnRequest
          xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
          xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
          ID="_73ffcfca-e08e-4a4c-88f5-2b8022c61bf2"
          IssueInstant="2012-10-11T12:06:28.0084232Z" Version="2.0"
          AssertionConsumerServiceIndex="2"&gt;</div>
        <div>&nbsp; &nbsp; &nbsp;
          &lt;saml:Issuer&gt;urn:federation:MicrosoftOnline&lt;/saml:Issuer&gt;</div>
        <div>&nbsp; &nbsp; &lt;/samlp:AuthnRequest&gt;</div>
        <div>&nbsp; &lt;/S:Body&gt;</div>
        <div>&lt;/S:Envelope&gt;</div>
      </div>
      <div><br>
      </div>
      <div>The problem is (I think) that there is no ACS URL with index
        2 listed in Microsoft's Windows Azure AD metadata at</div>
      <div><a moz-do-not-send="true" href="https://nexus.microsoftonline-p.com/federationmetadata/saml20/federationmetadata.xml">https://nexus.microsoftonline-p.com/federationmetadata/saml20/federationmetadata.xml</a></div>
    </blockquote>
    <br>
    In their example they have the following entry:<br>
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
    <pre>&lt;AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location=<a class="moz-txt-link-rfc2396E" href="https://login.microsoftonline.com/login.srf">"https://login.microsoftonline.com/login.srf"</a> index="2" /&gt;</pre>
    <a class="moz-txt-link-freetext" href="http://technet.microsoft.com/en-us/library/jj205463.aspx">http://technet.microsoft.com/en-us/library/jj205463.aspx</a><br>
    <br>
    Adding this in should fix the problem.<br>
    <br>
  </div>

</blockquote></div><br><div>You are absolutely right. I was using their online metadata, expecting that to be the same as the verbatim metadata in their docs.</div><div>Thanks for pointing this out.</div><div>--</div><div>Joost</div><div><br></div></body></html>