<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><span>OK, adding this:</span></div><div style="font-family: arial, helvetica, sans-serif; font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; font-style: normal;"><span><br></span></div><div style="background-color: transparent;"><span><div style="background-color: transparent;"><span style="font-weight: bold;"><span class="Apple-tab-span" style="white-space: pre;">                </span>&lt;RelyingParty Name="https://fidp.usc.edu.au/idp/shibboleth" keyName="AAF"/&gt;</span></div><div style="background-color: transparent;"><br></div><div style="background-color: transparent;"><span class="Apple-tab-span" style="white-space:pre">                </span>&lt;CredentialResolver type="Chaining"&gt;</div><div style="background-color: transparent;">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;
 &nbsp; &nbsp;&lt;CredentialResolver type="File" keyName="Active" use="encryption"</div><div style="background-color: transparent;">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;key="C:\opt\shibboleth-sp\etc\shibboleth\sp-key-2011.pem"&nbsp;</div><div style="background-color: transparent;">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;certificate="C:\opt\shibboleth-sp\etc\shibboleth\sp-cert-2011.pem"/&gt;</div><div style="background-color: transparent;">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&lt;CredentialResolver type="File" keyName="AAF"&nbsp;</div><div style="background-color: transparent;">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;key="C:\opt\shibboleth-sp\etc\shibboleth\sp-key-AAF.pem"&nbsp;</div><div
 style="background-color: transparent;">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;certificate="C:\opt\shibboleth-sp\etc\shibboleth\sp-cert-AAF.pem"/&gt;</div><div style="background-color: transparent;">&nbsp; &nbsp; &nbsp; &nbsp; &lt;/CredentialResolver&gt;</div></span></div><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><br></div><div style="font-family: arial, helvetica, sans-serif; font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; font-style: normal;">Generates this error:</div><div style="font-family: arial, helvetica, sans-serif; font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; font-style: normal;"><br></div><div style="background-color: transparent;">2013-01-23 06:19:51 ERROR XMLTooling.ParserPool : error on line 438, column 28, message: element 'RelyingParty' is not allowed for content model
 '((Sessions,Errors,RelyingParty,Notify,Audience,MetadataProvider,TrustEngine,AttributeExtractor,AttributeResolver,AttributeFilter,CredentialResolver),ApplicationOverride)'<br></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal;"><br></div><div style="background-color: transparent; color: rgb(0, 0, 0); font-size: 16px; font-family: arial, helvetica, sans-serif; font-style: normal;">Oddly, my test SP that mirrors prod did not generate this error... &nbsp;Even after copying etc/shibboleth2.xml from prod to the test machine... &nbsp;Googled that error - not much out there...</div><div style="font-family: arial, helvetica, sans-serif; font-size: 16px; color: rgb(0, 0, 0); background-color: transparent; font-style: normal;"><br></div><div style="font-family: arial, helvetica, sans-serif; font-size: 16px; color: rgb(0, 0, 0); background-color: transparent;
 font-style: normal;"><br></div>  <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <font size="2" face="Arial"> <hr size="1">  <b><span style="font-weight:bold;">From:</span></b> "Cantor, Scott" &lt;cantor.2@osu.edu&gt;<br> <b><span style="font-weight: bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt; <br> <b><span style="font-weight: bold;">Sent:</span></b> Tuesday, January 22, 2013 6:11 PM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: Internation dateline issue<br> </font> </div> <br>
On 1/22/13 8:51 PM, "Mike Flynn" &lt;<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt; wrote:<br><br>&gt;So, for each member coming through this fed, I have to add a new relying<br>&gt;party rule?&nbsp; I can't match on .<a target="_blank" href="http://edu.au/">edu.au</a> as other schools need to come in as<br>&gt;private feds.<br><br>There's no way for the code to know what certificate it's supposed to use.<br><br>That's why this is such a bad model. When federations dictate credentials,<br>things don't work well.<br><br>But as I said, SAML 2 means no queries which means you don't need a<br>signing certificate. Unless you sign requests.<br><br>-- Scott<br><br><br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br> </div> </div> 
 </div></body></html>