<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">We are having issues with our IdP working with the SP https://proxy.ohiolink.edu/shibboleth. The people at OhioLINK are telling us that we are not sending an Issuer which they require. We do not have any specific settings in our IdP configurations
for https://proxy.ohiolink.edu/shibboleth and we are both members of the InCommon Federation. We are not intentionally not sending the Issuer. We are looking for reasons why we are not sending the Issuer and how to make our IdP send the Issuer to this SP.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">A few other things to note is that Shibboleth is using the SAML 1.0 browser post binding below. We use SAML2 with all other non-ohiolink SPs so I am not sure what is causing that to happen. Here are the 4 possibilities from their metadata
in the InCommon file:<o:p></o:p></p>
<p class="MsoNormal"><md:AssertionConsumerService xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://proxy.ohiolink.edu:9100/Shibboleth.sso/SAML2/POST" index="1"/><o:p></o:p></p>
<p class="MsoNormal"><md:AssertionConsumerService xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://proxy.ohiolink.edu:9100/Shibboleth.sso/SAML2/Artifact" index="2"/><o:p></o:p></p>
<p class="MsoNormal"><md:AssertionConsumerService xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://proxy.ohiolink.edu:9100/Shibboleth.sso/SAML/POST" index="3"/><o:p></o:p></p>
<p class="MsoNormal"><md:AssertionConsumerService xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://proxy.ohiolink.edu:9100/Shibboleth.sso/SAML/Artifact" index="4"/><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">There is an error in the IdP logs:<o:p></o:p></p>
<p class="MsoNormal">10:04:19.277 - ERROR [org.opensaml.ws.security.provider.MandatoryAuthenticatedMessageRule:37] - Inbound message issuer was not authenticated.<o:p></o:p></p>
<p class="MsoNormal">10:04:19.278 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml1.AttributeQueryProfileHandler:180] - Message did not meet security requirements<o:p></o:p></p>
<p class="MsoNormal">org.opensaml.ws.security.SecurityPolicyException: Inbound message issuer was not authenticated.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">One of the certificates in the InCommon Metadata file for https://proxy.ohiolink.edu/shibboleth had expired at the end of January, but that has since been updated in the file and we have the latest InCommon Metadata file.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Scott- I know Joseph from OARnet messaged you about part of this last week. He also mentioned that OSU uses SAML1 in their communication with OhioLINK.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal">Philip<o:p></o:p></p>
</div>
</body>
</html>