<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><br></div>I've now reinstalled two VMs running CentOS6 with selinux and iptables both disabled with the names idp3 and sp3 following instructions from <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPSPLocalTestInstall">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPSPLocalTestInstall</a>.<div><br></div><div style="text-align: left;">The only place I am aware I have deviated from the instructions is when told to:" <span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); ">Change the </span><code style="margin-top: 0px; color: rgb(51, 51, 51); font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); ">entityID</code><span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); "> on the </span><code style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); ">Intranet <SessionInitiator Location="Login"></code><span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); ">to </span><code style="margin-bottom: 0px; color: rgb(51, 51, 51); font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); "><a class="external-link" href="https://idp.machine/idp/shibboleth" rel="nofollow" style="color: rgb(50, 96, 186); outline: none; ">https://idp.machine/idp/shibboleth</a></code><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;">. This is your IdP's name, and will send users directly to your IdP's login service." This is referring to shibboleth2.xml on the SP but this section does not seem to exist. I have </span><span style="font-size: 13px; line-height: 17px;">updated</span><span style="font-size: 13px; line-height: 17.328125px;"> the SSO section as follows instead but would </span><span style="font-size: 13px; line-height: 17px;">appreciate</span><span style="font-size: 13px; line-height: 17.328125px;"> if someone could confirm if this is correct or not:</span></font></span></div><div style="text-align: left;"><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div style="text-align: left;"><span style="text-align: left; background-color: rgb(255, 255, 255); font-size: 13px; line-height: 17px;"><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><div> Configures SSO for a default IdP. To allow for >1 IdP, remove</div><div> entityID property and adjust discoveryURL to point to discovery service.</div><div> (Set discoveryProtocol to "WAYF" for legacy Shibboleth WAYF support.)</div><div> You can also override entityID on /Login query string, or in RequestMap/htaccess.</div><div> --></div><div> <SSO entityID="<a href="https://idp3.martyforrest.com/idp/shibboleth">https://idp3.martyforrest.com/idp/shibboleth</a>"</div><div> discoveryProtocol="SAMLDS" discoveryURL="<a href="https://ds.example.org/DS/WAYF">https://ds.example.org/DS/WAYF</a>"></div><div> SAML2 SAML1</div><div> </SSO></div><div> </div><div><br></div><div>(The full config file is below).</div><div><br></div><div>I am not getting as far as before with the following error when browsing to <a href="https://sp3.martyforrest.com/secure:">https://sp3.martyforrest.com/secure:</a></div><div><br></div><div><h1 style="font-size: 14pt; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; ">opensaml::saml2md::MetadataException</h1><p style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; ">The system encountered an error at Fri Apr 5 19:41:12 2013</p><p style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; ">To report this problem, please contact the site administrator at <a href="mailto:root@localhost">root@localhost</a>.</p><p style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; ">Please include the following message in any email:</p><p class="error" style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; font-weight: bold; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; ">opensaml::saml2md::MetadataException at (<a href="https://sp3.martyforrest.com/secure">https://sp3.martyforrest.com/secure</a>)</p><p class="error" style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; font-weight: bold; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; "><span style="font-size: 10pt; ">Unable to locate metadata for identity provider (<a href="https://idp3.martyforrest.com/idp/shibboleth">https://idp3.martyforrest.com/idp/shibboleth</a>)</span></p></div></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;">I cannot see any issued and would appreciate some help</span><span style="font-size: 13px; line-height: 17px;">…</span><span style="font-size: 13px; line-height: 17.328125px;">.</span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;">I have copied </span><span style="font-size: 13px; line-height: 17px;">the</span><span style="font-size: 13px; line-height: 17.328125px;"> shibboleth2.xml and the output from the remote metadata it used below</span></font></span><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17px;">…</span></font></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;">Apologies for the length of the post.</span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;">Dom</span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div style="text-align: left;"><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17px;"><b>shibboleth2.xml from SP</b></span></font></div><div style="text-align: left;"><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17px;"><div><SPConfig xmlns="urn:mace:shibboleth:2.0:native:sp:config"</div><div> xmlns:conf="urn:mace:shibboleth:2.0:native:sp:config"</div><div> xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"</div><div> xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" </div><div> xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"</div><div> clockSkew="180"></div><div><br></div><div> <!--</div><div> By default, in-memory StorageService, ReplayCache, ArtifactMap, and SessionCache</div><div> are used. See example-shibboleth2.xml for samples of explicitly configuring them.</div><div> --></div><div><br></div><div> <!--</div><div> To customize behavior for specific resources on Apache, and to link vhosts or</div><div> resources to ApplicationOverride settings below, use web server options/commands.</div><div> See <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPConfigurationElements">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPConfigurationElements</a> for help.</div><div> </div><div> For examples with the RequestMap XML syntax instead, see the example-shibboleth2.xml</div><div> file, and the <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRequestMapHowTo">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRequestMapHowTo</a> topic.</div><div> --></div><div><br></div><div> <!-- The ApplicationDefaults element is where most of Shibboleth's SAML bits are defined. --></div><div> <ApplicationDefaults entityID="<a href="https://sp3.martyforrest.com/shibboleth">https://sp3.martyforrest.com/shibboleth</a>"</div><div> REMOTE_USER="eppn persistent-id targeted-id"></div><div><br></div><div> <!--</div><div> Controls session lifetimes, address checks, cookie handling, and the protocol handlers.</div><div> You MUST supply an effectively unique handlerURL value for each of your applications.</div><div> The value defaults to /Shibboleth.sso, and should be a relative path, with the SP computing</div><div> a relative value based on the virtual host. Using handlerSSL="true", the default, will force</div><div> the protocol to be https. You should also set cookieProps to "https" for SSL-only sites.</div><div> Note that while we default checkAddress to "false", this has a negative impact on the</div><div> security of your site. Stealing sessions via cookie theft is much easier with this disabled.</div><div> --></div><div> <Sessions lifetime="28800" timeout="3600" relayState="ss:mem"</div><div> checkAddress="false" handlerSSL="false" cookieProps="http"></div><div><br></div><div> <!--</div><div> Configures SSO for a default IdP. To allow for >1 IdP, remove</div><div> entityID property and adjust discoveryURL to point to discovery service.</div><div> (Set discoveryProtocol to "WAYF" for legacy Shibboleth WAYF support.)</div><div> You can also override entityID on /Login query string, or in RequestMap/htaccess.</div><div> --></div><div> <SSO entityID="<a href="https://idp3.martyforrest.com/idp/shibboleth">https://idp3.martyforrest.com/idp/shibboleth</a>"</div><div> discoveryProtocol="SAMLDS" discoveryURL="<a href="https://ds.example.org/DS/WAYF">https://ds.example.org/DS/WAYF</a>"></div><div> SAML2 SAML1</div><div> </SSO></div><div><br></div><div> <!-- SAML and local-only logout. --></div><div> <Logout>SAML2 Local</Logout></div><div> </div><div> <!-- Extension service that generates "approximate" metadata based on SP configuration. --></div><div> <Handler type="MetadataGenerator" Location="/Metadata" signing="false"/></div><div><br></div><div> <!-- Status reporting service. --></div><div> <Handler type="Status" Location="/Status" acl="127.0.0.1 ::1"/></div><div><br></div><div> <!-- Session diagnostic service. --></div><div> <Handler type="Session" Location="/Session" showAttributeValues="false"/></div><div><br></div><div> <!-- JSON feed of discovery information. --></div><div> <Handler type="DiscoveryFeed" Location="/DiscoFeed"/></div><div> </Sessions></div><div><br></div><div> <!--</div><div> Allows overriding of error template information/filenames. You can</div><div> also add attributes with values that can be plugged into the templates.</div><div> --></div><div> <Errors supportContact="root@localhost"</div><div> helpLocation="/about.html"</div><div> styleSheet="/shibboleth-sp/main.css"/></div><div> </div><div> <!-- Example of remotely supplied batch of signed metadata. --></div><div> </div><div> <MetadataProvider type="XML" uri="<a href="https://idp3.martyforrest.com/idp/profile/Metadata/SAML">https://idp3.martyforrest.com/idp/profile/Metadata/SAML</a>"</div><div> backingFilePath="federation-metadata.xml" reloadInterval="7200"></div><div> <MetadataFilter type="RequireValidUntil" maxValidityInterval="2419200"/></div><div> </MetadataProvider></div><div> </div><div><br></div><div> <!-- Example of locally maintained metadata. --></div><div> <!--</div><div> <MetadataProvider type="XML" file="partner-metadata.xml"/></div><div> --></div><div><br></div><div> <!-- Map to extract attributes from SAML assertions. --></div><div> <AttributeExtractor type="XML" validate="true" reloadChanges="false" path="attribute-map.xml"/></div><div> </div><div> <!-- Use a SAML query if no attributes are supplied during SSO. --></div><div> <AttributeResolver type="Query" subjectMatch="true"/></div><div><br></div><div> <!-- Default filtering policy for recognized attributes, lets other data pass. --></div><div> <AttributeFilter type="XML" validate="true" path="attribute-policy.xml"/></div><div><br></div><div> <!-- Simple file-based resolver for using a single keypair. --></div><div> <CredentialResolver type="File" key="sp-key.pem" certificate="sp-cert.pem"/></div><div><br></div><div> <!--</div><div> The default settings can be overridden by creating ApplicationOverride elements (see</div><div> the <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPApplicationOverride">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPApplicationOverride</a> topic).</div><div> Resource requests are mapped by web server commands, or the RequestMapper, to an</div><div> applicationId setting.</div><div> </div><div> Example of a second application (for a second vhost) that has a different entityID.</div><div> Resources on the vhost would map to an applicationId of "admin":</div><div> --></div><div> <!--</div><div> <ApplicationOverride id="admin" entityID="<a href="https://admin.example.org/shibboleth">https://admin.example.org/shibboleth</a>"/></div><div> --></div><div> </ApplicationDefaults></div><div> </div><div> <!-- Policies that determine how to process and authenticate runtime messages. --></div><div> <SecurityPolicyProvider type="XML" validate="true" path="security-policy.xml"/></div><div><br></div><div> <!-- Low-level configuration about protocols and bindings available for use. --></div><div> <ProtocolProvider type="XML" validate="true" reloadChanges="false" path="protocols.xml"/></div><div><br></div><div></SPConfig></div></span></font></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 17px; text-align: left; "><b><a href="https://idp3.martyforrest.com/idp/profile/Metadata/SAML">https://idp3.martyforrest.com/idp/profile/Metadata/SAML</a></b></span></div><div><div class="line" style="font-family: monospace; font-size: 13px; "><span class="webkit-html-tag"><EntityDescriptor<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">xmlns</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:metadata</span>"</span><span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">xmlns:ds</span>="<span class="webkit-html-attribute-value"><a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a></span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">xmlns:shibmd</span>="<span class="webkit-html-attribute-value">urn:mace:shibboleth:metadata:1.0</span>"</span><span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">xmlns:xsi</span>="<span class="webkit-html-attribute-value"><a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a></span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">entityID</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com/idp/shibboleth">https://idp3.martyforrest.com/idp/shibboleth</a></span>"</span>></span></div><div class="collapsible-content" style="margin-left: 1em; font-family: monospace; font-size: 13px; "><div class="collapsible" id="collapsible1"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><IDPSSODescriptor<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">protocolSupportEnumeration</span>="<span class="webkit-html-attribute-value">urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol</span>"</span>></span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible2"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><Extensions></span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="line"><span class="webkit-html-tag"><shibmd:Scope<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">regexp</span>="<span class="webkit-html-attribute-value">false</span>"</span>></span><span class="text"><a href="http://martyforrest.com">martyforrest.com</a></span><span class="webkit-html-tag"></shibmd:Scope></span></div></div><div class="line"><span class="webkit-html-tag"></Extensions></span></div></div></div><div class="collapsible" id="collapsible3"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><KeyDescriptor></span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible4"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><ds:KeyInfo></span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible5"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><ds:X509Data></span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible6"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><ds:X509Certificate></span></div><div class="collapsible-content" style="margin-left: 1em;"><span class="text">MIIDPzCCAiegAwIBAgIUI62qgIbhVfiZdfyZGFxI6rGREhYwDQYJKoZIhvcNAQEF BQAwIDEeMBwGA1UEAxMVaWRwMy5tYXJ0eWZvcnJlc3QuY29tMB4XDTEzMDQwNTE1 NTE0N1oXDTMzMDQwNTE1NTE0N1owIDEeMBwGA1UEAxMVaWRwMy5tYXJ0eWZvcnJl c3QuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAhDHis7lgZoph agviGBeUKWm4TNvAZtKeH8DqijCt69LuQxvcIUfOINyKZiBtwWT3fNzsRTNJFkoa U/2vkr8jOZhS3dWLI7WvCeBolF930feAGmwSR8S0cm6Ndls6QRx9O9A5Ng8nEaGS iFvddR8iDnmnQgXJ0VGnUE/6J6zqgSbPI3G58SieSwCwpTw5Aq5j3q469GaxULEw Oggls46XOsF7gb0j21RtvzGuX3h1kEIFemjw6Zan2ng7hlScVeTuZsWKv/Lz+t8f jO1McuuMPdFGA4JfPO5fHseCfkUW4nnV6rjPSw9AUXidcwzdVcTt8bj91Z+//2DM kcgglB4vxwIDAQABo3EwbzBOBgNVHREERzBFghVpZHAzLm1hcnR5Zm9ycmVzdC5j b22GLGh0dHBzOi8vaWRwMy5tYXJ0eWZvcnJlc3QuY29tL2lkcC9zaGliYm9sZXRo MB0GA1UdDgQWBBSgNBL8gHZ4tGxRXQBNAP9RHOj89TANBgkqhkiG9w0BAQUFAAOC AQEAP4KzSWGMZTxecA3akK/fiKvq1Hr1iqk2r7C2H/KK2HpUTgBJ2CHNEGzGp3Qx +nAFCTXjEwUmlHpmeiRX6mANfOTmZnKl2MD7O5apNIFS/xYdj3P5eKt7OYISGCjG 5zkXgWdGBkM+LaFiXBA2ZC/QnbSFupY2hGbO9EnoNynASwxmtwKoUElhqwZ5LsVW TYPHcvoFcwlNx8530Futj4ldlMUaNs4OuHxXIrQUg9gPFXLeKaceGD3DP/eJv7J6 9Xy/oEh87FUX0/gTRmfP9eewMBEbX0zrRxlo3VwsOcNMtHv1gLgAjfRfmbiOzBmu R4TQzLmCoAtjMz+PTtKIu8s0Wg==</span></div><div class="line"><span class="webkit-html-tag"></ds:X509Certificate></span></div></div></div></div><div class="line"><span class="webkit-html-tag"></ds:X509Data></span></div></div></div></div><div class="line"><span class="webkit-html-tag"></ds:KeyInfo></span></div></div></div></div><div class="line"><span class="webkit-html-tag"></KeyDescriptor></span></div></div></div><div class="line"><span class="webkit-html-tag"><ArtifactResolutionService<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com:8443/idp/profile/SAML1/SOAP/ArtifactResolution">https://idp3.martyforrest.com:8443/idp/profile/SAML1/SOAP/ArtifactResolution</a></span>"</span><span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">index</span>="<span class="webkit-html-attribute-value">1</span>"</span>/></span></div><div class="line"><span class="webkit-html-tag"><ArtifactResolutionService<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:bindings:SOAP</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com:8443/idp/profile/SAML2/SOAP/ArtifactResolution">https://idp3.martyforrest.com:8443/idp/profile/SAML2/SOAP/ArtifactResolution</a></span>"</span><span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">index</span>="<span class="webkit-html-attribute-value">2</span>"</span>/></span></div><div class="line"><span class="webkit-html-tag"><NameIDFormat></span><span class="text">urn:mace:shibboleth:1.0:nameIdentifier</span><span class="webkit-html-tag"></NameIDFormat></span></div><div class="collapsible" id="collapsible7"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><NameIDFormat></span></div><div class="collapsible-content" style="margin-left: 1em;"><span class="text">urn:oasis:names:tc:SAML:2.0:nameid-format:transient</span></div><div class="line"><span class="webkit-html-tag"></NameIDFormat></span></div></div></div><div class="line"><span class="webkit-html-tag"><SingleSignOnService<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:mace:shibboleth:1.0:profiles:AuthnRequest</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com/idp/profile/Shibboleth/SSO">https://idp3.martyforrest.com/idp/profile/Shibboleth/SSO</a></span>"</span>/></span></div><div class="line"><span class="webkit-html-tag"><SingleSignOnService<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com/idp/profile/SAML2/POST/SSO">https://idp3.martyforrest.com/idp/profile/SAML2/POST/SSO</a></span>"</span>/></span></div><div class="line"><span class="webkit-html-tag"><SingleSignOnService<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com/idp/profile/SAML2/POST-SimpleSign/SSO">https://idp3.martyforrest.com/idp/profile/SAML2/POST-SimpleSign/SSO</a></span>"</span>/></span></div><div class="line"><span class="webkit-html-tag"><SingleSignOnService<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com/idp/profile/SAML2/Redirect/SSO">https://idp3.martyforrest.com/idp/profile/SAML2/Redirect/SSO</a></span>"</span>/></span></div></div><div class="line"><span class="webkit-html-tag"></IDPSSODescriptor></span></div></div></div><div class="collapsible" id="collapsible8"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><AttributeAuthorityDescriptor<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">protocolSupportEnumeration</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol</span>"</span>></span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible9"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><Extensions></span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="line"><span class="webkit-html-tag"><shibmd:Scope<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">regexp</span>="<span class="webkit-html-attribute-value">false</span>"</span>></span><span class="text"><a href="http://martyforrest.com">martyforrest.com</a></span><span class="webkit-html-tag"></shibmd:Scope></span></div></div><div class="line"><span class="webkit-html-tag"></Extensions></span></div></div></div><div class="collapsible" id="collapsible10"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><KeyDescriptor></span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible11"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><ds:KeyInfo></span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible12"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><ds:X509Data></span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible13"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><ds:X509Certificate></span></div><div class="collapsible-content" style="margin-left: 1em;"><span class="text">MIIDPzCCAiegAwIBAgIUI62qgIbhVfiZdfyZGFxI6rGREhYwDQYJKoZIhvcNAQEF BQAwIDEeMBwGA1UEAxMVaWRwMy5tYXJ0eWZvcnJlc3QuY29tMB4XDTEzMDQwNTE1 NTE0N1oXDTMzMDQwNTE1NTE0N1owIDEeMBwGA1UEAxMVaWRwMy5tYXJ0eWZvcnJl c3QuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAhDHis7lgZoph agviGBeUKWm4TNvAZtKeH8DqijCt69LuQxvcIUfOINyKZiBtwWT3fNzsRTNJFkoa U/2vkr8jOZhS3dWLI7WvCeBolF930feAGmwSR8S0cm6Ndls6QRx9O9A5Ng8nEaGS iFvddR8iDnmnQgXJ0VGnUE/6J6zqgSbPI3G58SieSwCwpTw5Aq5j3q469GaxULEw Oggls46XOsF7gb0j21RtvzGuX3h1kEIFemjw6Zan2ng7hlScVeTuZsWKv/Lz+t8f jO1McuuMPdFGA4JfPO5fHseCfkUW4nnV6rjPSw9AUXidcwzdVcTt8bj91Z+//2DM kcgglB4vxwIDAQABo3EwbzBOBgNVHREERzBFghVpZHAzLm1hcnR5Zm9ycmVzdC5j b22GLGh0dHBzOi8vaWRwMy5tYXJ0eWZvcnJlc3QuY29tL2lkcC9zaGliYm9sZXRo MB0GA1UdDgQWBBSgNBL8gHZ4tGxRXQBNAP9RHOj89TANBgkqhkiG9w0BAQUFAAOC AQEAP4KzSWGMZTxecA3akK/fiKvq1Hr1iqk2r7C2H/KK2HpUTgBJ2CHNEGzGp3Qx +nAFCTXjEwUmlHpmeiRX6mANfOTmZnKl2MD7O5apNIFS/xYdj3P5eKt7OYISGCjG 5zkXgWdGBkM+LaFiXBA2ZC/QnbSFupY2hGbO9EnoNynASwxmtwKoUElhqwZ5LsVW TYPHcvoFcwlNx8530Futj4ldlMUaNs4OuHxXIrQUg9gPFXLeKaceGD3DP/eJv7J6 9Xy/oEh87FUX0/gTRmfP9eewMBEbX0zrRxlo3VwsOcNMtHv1gLgAjfRfmbiOzBmu R4TQzLmCoAtjMz+PTtKIu8s0Wg==</span></div><div class="line"><span class="webkit-html-tag"></ds:X509Certificate></span></div></div></div></div><div class="line"><span class="webkit-html-tag"></ds:X509Data></span></div></div></div></div><div class="line"><span class="webkit-html-tag"></ds:KeyInfo></span></div></div></div></div><div class="line"><span class="webkit-html-tag"></KeyDescriptor></span></div></div></div><div class="line"><span class="webkit-html-tag"><AttributeService<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com:8443/idp/profile/SAML1/SOAP/AttributeQuery">https://idp3.martyforrest.com:8443/idp/profile/SAML1/SOAP/AttributeQuery</a></span>"</span>/></span></div><div class="line"><span class="webkit-html-tag"><AttributeService<span class="webkit-html-attribute"> <span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:bindings:SOAP</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com:8443/idp/profile/SAML2/SOAP/AttributeQuery">https://idp3.martyforrest.com:8443/idp/profile/SAML2/SOAP/AttributeQuery</a></span>"</span>/></span></div><div class="line"><span class="webkit-html-tag"><NameIDFormat></span><span class="text">urn:mace:shibboleth:1.0:nameIdentifier</span><span class="webkit-html-tag"></NameIDFormat></span></div><div class="collapsible" id="collapsible14"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag"><NameIDFormat></span></div><div class="collapsible-content" style="margin-left: 1em;"><span class="text">urn:oasis:names:tc:SAML:2.0:nameid-format:transient</span></div><div class="line"><span class="webkit-html-tag"></NameIDFormat></span></div></div></div></div><div class="line"><span class="webkit-html-tag"></AttributeAuthorityDescriptor></span></div></div></div></div><div class="line" style="font-family: monospace; font-size: 13px; "><span class="webkit-html-tag"></EntityDescriptor></span></div></div><div><span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); "><br></span></div><div><br></div><div><br><div><div>On 5 Apr 2013, at 14:53, Dominic Forrest <<a href="mailto:dom.forrest@gmail.com">dom.forrest@gmail.com</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><br>Thankyou. I think I'll go back to basics on this and start agin on CentOS…. I appreciate your help but fear I may have some future questions…<br><br><br>Dom<br><br><br>On 5 Apr 2013, at 14:51, Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br><br><blockquote type="cite">I don't have an explanation yet. The snipplets you've sent so far seem<br>to be OK. The IdP seems to load the SP's metadata and vice versa. The<br>metadata for the SP looks fine.<br>So something in your deployment is off.<br><br>Note that you're running on an unsupported (by the Shibboleth project)<br>platform and did not follow the locally installed documentation.<br>I'm pretty sure Ubuntu (taking it from Debian) mentions to run the<br>shib-keygen command after installation, in which case your SP's<br>metadata would have also contained its public key. Jfyi.<br><br>* Dominic Forrest <<a href="mailto:dom.forrest@gmail.com">dom.forrest@gmail.com</a>> [2013-04-05 15:22]:<br><blockquote type="cite"> <metadata:MetadataProvider id="URLMD" xsi:type="metadata:FileBackedHTTPMetadataProvider"<br> metadataURL="<a href="https://sp.zzz.com/Shibboleth.sso/Metadata">https://sp.zzz.com/Shibboleth.sso/Metadata</a>"<br> backingFile="/opt/shibboleth-idp/metadata/some-metadata.xml"><br> <metadata:MetadataFilter xsi:type="metadata:ChainingFilter"><br> <metadata:MetadataFilter xsi:type="metadata:EntityRoleWhiteList"><br> <metadata:RetainedRole>samlmd:SPSSODescriptor</metadata:RetainedRole><br> </metadata:MetadataFilter><br> </metadata:MetadataFilter><br> </metadata:MetadataProvider><br></blockquote><br>Jfyi, the metadata generated from the SP will never contain anything<br>else but an SPSSODescriptor, so you can remove the filter (and the<br>surrounding chaining filter as it would be empty then).<br><br>Maybe the IdP is not yet actually using the changed relying-partyx.xml<br>config (requires a restart of the context or container) -- is the<br>backingFile specified above being generated properly?<br><br><blockquote type="cite"><!--<br>This is example metadata only. Do *NOT* supply it as is without review,<br>and do *NOT* provide it in real time to your partners.<br>--><br></blockquote><br>Yes, so much for that.<br><br>Note that your IdP logged:<br><br> No return endpoint available for relying party <a href="https://sp.zzz.com">https://sp.zzz.com</a><br><br>but your SP config had:<br><br> entityID="<a href="https://sp.xxx.com">https://sp.xxx.com</a>"<br><br>I suppose that's just because you don't want to use RFC 2606 host<br>names in emails and you messed up the pseudonymization in your<br>examples. (The SP's metadata also had zzz.)<br><br><blockquote type="cite">What I do not understand is how this is being generated by the SP<br>however t appears I would be better saving this locally on the IDP<br>and (with help) editing as appropriate?<br></blockquote><br>Not your issue currently and will only come up later. I thought there<br>was a wiki page for that (which then should be linked from that XML<br>comment) but can't fint it atm.<br>Ignore that for now, or search the list archives.<br>-peter<br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote><br></blockquote></div><br></div></body></html>