<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><br></div>I've now reinstalled two VMs running CentOS6 with selinux and iptables both disabled with the names idp3 and sp3 following instructions from&nbsp;<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPSPLocalTestInstall">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPSPLocalTestInstall</a>.<div><br></div><div style="text-align: left;">The only place I am aware I have deviated from the instructions is when told to:"&nbsp;<span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); ">Change the&nbsp;</span><code style="margin-top: 0px; color: rgb(51, 51, 51); font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); ">entityID</code><span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); ">&nbsp;on the&nbsp;</span><code style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); ">Intranet &lt;SessionInitiator Location="Login"&gt;</code><span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); ">to&nbsp;</span><code style="margin-bottom: 0px; color: rgb(51, 51, 51); font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); "><a class="external-link" href="https://idp.machine/idp/shibboleth" rel="nofollow" style="color: rgb(50, 96, 186); outline: none; ">https://idp.machine/idp/shibboleth</a></code><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;">. This is your IdP's name, and will send users directly to your IdP's login service." &nbsp;This is referring to shibboleth2.xml on the SP but this section does not seem to exist. &nbsp;I have&nbsp;</span><span style="font-size: 13px; line-height: 17px;">updated</span><span style="font-size: 13px; line-height: 17.328125px;">&nbsp;the SSO section as follows instead but would&nbsp;</span><span style="font-size: 13px; line-height: 17px;">appreciate</span><span style="font-size: 13px; line-height: 17.328125px;">&nbsp;if someone could confirm if this is correct or not:</span></font></span></div><div style="text-align: left;"><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div style="text-align: left;"><span style="text-align: left; background-color: rgb(255, 255, 255); font-size: 13px; line-height: 17px;"><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Configures SSO for a default IdP. To allow for &gt;1 IdP, remove</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; entityID property and adjust discoveryURL to point to discovery service.</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; (Set discoveryProtocol to "WAYF" for legacy Shibboleth WAYF support.)</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; You can also override entityID on /Login query string, or in RequestMap/htaccess.</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SSO entityID="<a href="https://idp3.martyforrest.com/idp/shibboleth">https://idp3.martyforrest.com/idp/shibboleth</a>"</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;discoveryProtocol="SAMLDS" discoveryURL="<a href="https://ds.example.org/DS/WAYF">https://ds.example.org/DS/WAYF</a>"&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; SAML2 SAML1</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/SSO&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;</div><div><br></div><div>(The full config file is below).</div><div><br></div><div>I am not getting as far as before with the following error when browsing to <a href="https://sp3.martyforrest.com/secure:">https://sp3.martyforrest.com/secure:</a></div><div><br></div><div><h1 style="font-size: 14pt; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; ">opensaml::saml2md::MetadataException</h1><p style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; ">The system encountered an error at Fri Apr 5 19:41:12 2013</p><p style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; ">To report this problem, please contact the site administrator at&nbsp;<a href="mailto:root@localhost">root@localhost</a>.</p><p style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; ">Please include the following message in any email:</p><p class="error" style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; font-weight: bold; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; ">opensaml::saml2md::MetadataException at (<a href="https://sp3.martyforrest.com/secure">https://sp3.martyforrest.com/secure</a>)</p><p class="error" style="font-size: 10pt; margin-top: 20px; margin-bottom: 20px; font-weight: bold; color: rgb(0, 0, 0); font-family: Geneva, Arial, Helvetica, sans-serif; line-height: normal; "><span style="font-size: 10pt; ">Unable to locate metadata for identity provider (<a href="https://idp3.martyforrest.com/idp/shibboleth">https://idp3.martyforrest.com/idp/shibboleth</a>)</span></p></div></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;">I cannot see any issued and would appreciate some help</span><span style="font-size: 13px; line-height: 17px;">…</span><span style="font-size: 13px; line-height: 17.328125px;">.</span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;">I have copied&nbsp;</span><span style="font-size: 13px; line-height: 17px;">the</span><span style="font-size: 13px; line-height: 17.328125px;">&nbsp;shibboleth2.xml and the output from the remote metadata it used below</span></font></span><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17px;">…</span></font></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;">Apologies for the length of the post.</span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;">Dom</span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div style="text-align: left;"><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17px;"><b>shibboleth2.xml from SP</b></span></font></div><div style="text-align: left;"><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17px;"><div>&lt;SPConfig xmlns="urn:mace:shibboleth:2.0:native:sp:config"</div><div>&nbsp; &nbsp; xmlns:conf="urn:mace:shibboleth:2.0:native:sp:config"</div><div>&nbsp; &nbsp; xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"</div><div>&nbsp; &nbsp; xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" &nbsp; &nbsp;</div><div>&nbsp; &nbsp; xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"</div><div>&nbsp; &nbsp; clockSkew="180"&gt;</div><div><br></div><div>&nbsp; &nbsp; &lt;!--</div><div>&nbsp; &nbsp; By default, in-memory StorageService, ReplayCache, ArtifactMap, and SessionCache</div><div>&nbsp; &nbsp; are used. See example-shibboleth2.xml for samples of explicitly configuring them.</div><div>&nbsp; &nbsp; --&gt;</div><div><br></div><div>&nbsp; &nbsp; &lt;!--</div><div>&nbsp; &nbsp; To customize behavior for specific resources on Apache, and to link vhosts or</div><div>&nbsp; &nbsp; resources to ApplicationOverride settings below, use web server options/commands.</div><div>&nbsp; &nbsp; See <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPConfigurationElements">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPConfigurationElements</a> for help.</div><div>&nbsp; &nbsp;&nbsp;</div><div>&nbsp; &nbsp; For examples with the RequestMap XML syntax instead, see the example-shibboleth2.xml</div><div>&nbsp; &nbsp; file, and the <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRequestMapHowTo">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRequestMapHowTo</a> topic.</div><div>&nbsp; &nbsp; --&gt;</div><div><br></div><div>&nbsp; &nbsp; &lt;!-- The ApplicationDefaults element is where most of Shibboleth's SAML bits are defined. --&gt;</div><div>&nbsp; &nbsp; &lt;ApplicationDefaults entityID="<a href="https://sp3.martyforrest.com/shibboleth">https://sp3.martyforrest.com/shibboleth</a>"</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;REMOTE_USER="eppn persistent-id targeted-id"&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!--</div><div>&nbsp; &nbsp; &nbsp; &nbsp; Controls session lifetimes, address checks, cookie handling, and the protocol handlers.</div><div>&nbsp; &nbsp; &nbsp; &nbsp; You MUST supply an effectively unique handlerURL value for each of your applications.</div><div>&nbsp; &nbsp; &nbsp; &nbsp; The value defaults to /Shibboleth.sso, and should be a relative path, with the SP computing</div><div>&nbsp; &nbsp; &nbsp; &nbsp; a relative value based on the virtual host. Using handlerSSL="true", the default, will force</div><div>&nbsp; &nbsp; &nbsp; &nbsp; the protocol to be https. You should also set cookieProps to "https" for SSL-only sites.</div><div>&nbsp; &nbsp; &nbsp; &nbsp; Note that while we default checkAddress to "false", this has a negative impact on the</div><div>&nbsp; &nbsp; &nbsp; &nbsp; security of your site. Stealing sessions via cookie theft is much easier with this disabled.</div><div>&nbsp; &nbsp; &nbsp; &nbsp; --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;Sessions lifetime="28800" timeout="3600" relayState="ss:mem"</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; checkAddress="false" handlerSSL="false" cookieProps="http"&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!--</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Configures SSO for a default IdP. To allow for &gt;1 IdP, remove</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; entityID property and adjust discoveryURL to point to discovery service.</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; (Set discoveryProtocol to "WAYF" for legacy Shibboleth WAYF support.)</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; You can also override entityID on /Login query string, or in RequestMap/htaccess.</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;SSO entityID="<a href="https://idp3.martyforrest.com/idp/shibboleth">https://idp3.martyforrest.com/idp/shibboleth</a>"</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;discoveryProtocol="SAMLDS" discoveryURL="<a href="https://ds.example.org/DS/WAYF">https://ds.example.org/DS/WAYF</a>"&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; SAML2 SAML1</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;/SSO&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- SAML and local-only logout. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Logout&gt;SAML2 Local&lt;/Logout&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Extension service that generates "approximate" metadata based on SP configuration. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Handler type="MetadataGenerator" Location="/Metadata" signing="false"/&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Status reporting service. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Handler type="Status" Location="/Status" acl="127.0.0.1 ::1"/&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Session diagnostic service. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Handler type="Session" Location="/Session" showAttributeValues="false"/&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- JSON feed of discovery information. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;Handler type="DiscoveryFeed" Location="/DiscoFeed"/&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;/Sessions&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!--</div><div>&nbsp; &nbsp; &nbsp; &nbsp; Allows overriding of error template information/filenames. You can</div><div>&nbsp; &nbsp; &nbsp; &nbsp; also add attributes with values that can be plugged into the templates.</div><div>&nbsp; &nbsp; &nbsp; &nbsp; --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;Errors supportContact="root@localhost"</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; helpLocation="/about.html"</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; styleSheet="/shibboleth-sp/main.css"/&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Example of remotely supplied batch of signed metadata. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;MetadataProvider type="XML" uri="<a href="https://idp3.martyforrest.com/idp/profile/Metadata/SAML">https://idp3.martyforrest.com/idp/profile/Metadata/SAML</a>"</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; backingFilePath="federation-metadata.xml" reloadInterval="7200"&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;MetadataFilter type="RequireValidUntil" maxValidityInterval="2419200"/&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;/MetadataProvider&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Example of locally maintained metadata. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!--</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;MetadataProvider type="XML" file="partner-metadata.xml"/&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; --&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Map to extract attributes from SAML assertions. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;AttributeExtractor type="XML" validate="true" reloadChanges="false" path="attribute-map.xml"/&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Use a SAML query if no attributes are supplied during SSO. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;AttributeResolver type="Query" subjectMatch="true"/&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Default filtering policy for recognized attributes, lets other data pass. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;AttributeFilter type="XML" validate="true" path="attribute-policy.xml"/&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!-- Simple file-based resolver for using a single keypair. --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;CredentialResolver type="File" key="sp-key.pem" certificate="sp-cert.pem"/&gt;</div><div><br></div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!--</div><div>&nbsp; &nbsp; &nbsp; &nbsp; The default settings can be overridden by creating ApplicationOverride elements (see</div><div>&nbsp; &nbsp; &nbsp; &nbsp; the <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPApplicationOverride">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPApplicationOverride</a> topic).</div><div>&nbsp; &nbsp; &nbsp; &nbsp; Resource requests are mapped by web server commands, or the RequestMapper, to an</div><div>&nbsp; &nbsp; &nbsp; &nbsp; applicationId setting.</div><div>&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; Example of a second application (for a second vhost) that has a different entityID.</div><div>&nbsp; &nbsp; &nbsp; &nbsp; Resources on the vhost would map to an applicationId of "admin":</div><div>&nbsp; &nbsp; &nbsp; &nbsp; --&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;!--</div><div>&nbsp; &nbsp; &nbsp; &nbsp; &lt;ApplicationOverride id="admin" entityID="<a href="https://admin.example.org/shibboleth">https://admin.example.org/shibboleth</a>"/&gt;</div><div>&nbsp; &nbsp; &nbsp; &nbsp; --&gt;</div><div>&nbsp; &nbsp; &lt;/ApplicationDefaults&gt;</div><div>&nbsp; &nbsp;&nbsp;</div><div>&nbsp; &nbsp; &lt;!-- Policies that determine how to process and authenticate runtime messages. --&gt;</div><div>&nbsp; &nbsp; &lt;SecurityPolicyProvider type="XML" validate="true" path="security-policy.xml"/&gt;</div><div><br></div><div>&nbsp; &nbsp; &lt;!-- Low-level configuration about protocols and bindings available for use. --&gt;</div><div>&nbsp; &nbsp; &lt;ProtocolProvider type="XML" validate="true" reloadChanges="false" path="protocols.xml"/&gt;</div><div><br></div><div>&lt;/SPConfig&gt;</div></span></font></div><div><span style="text-align: left; background-color: rgb(255, 255, 255); "><font color="#333333" face="Arial, Helvetica, FreeSans, sans-serif"><span style="font-size: 13px; line-height: 17.328125px;"><br></span></font></span></div><div><span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 17px; text-align: left; "><b><a href="https://idp3.martyforrest.com/idp/profile/Metadata/SAML">https://idp3.martyforrest.com/idp/profile/Metadata/SAML</a></b></span></div><div><div class="line" style="font-family: monospace; font-size: 13px; "><span class="webkit-html-tag">&lt;EntityDescriptor<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">xmlns</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:metadata</span>"</span><span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">xmlns:ds</span>="<span class="webkit-html-attribute-value"><a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a></span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">xmlns:shibmd</span>="<span class="webkit-html-attribute-value">urn:mace:shibboleth:metadata:1.0</span>"</span><span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">xmlns:xsi</span>="<span class="webkit-html-attribute-value"><a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a></span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">entityID</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com/idp/shibboleth">https://idp3.martyforrest.com/idp/shibboleth</a></span>"</span>&gt;</span></div><div class="collapsible-content" style="margin-left: 1em; font-family: monospace; font-size: 13px; "><div class="collapsible" id="collapsible1"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;IDPSSODescriptor<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">protocolSupportEnumeration</span>="<span class="webkit-html-attribute-value">urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol</span>"</span>&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible2"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;Extensions&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="line"><span class="webkit-html-tag">&lt;shibmd:Scope<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">regexp</span>="<span class="webkit-html-attribute-value">false</span>"</span>&gt;</span><span class="text"><a href="http://martyforrest.com">martyforrest.com</a></span><span class="webkit-html-tag">&lt;/shibmd:Scope&gt;</span></div></div><div class="line"><span class="webkit-html-tag">&lt;/Extensions&gt;</span></div></div></div><div class="collapsible" id="collapsible3"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;KeyDescriptor&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible4"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;ds:KeyInfo&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible5"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;ds:X509Data&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible6"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;ds:X509Certificate&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><span class="text">MIIDPzCCAiegAwIBAgIUI62qgIbhVfiZdfyZGFxI6rGREhYwDQYJKoZIhvcNAQEF BQAwIDEeMBwGA1UEAxMVaWRwMy5tYXJ0eWZvcnJlc3QuY29tMB4XDTEzMDQwNTE1 NTE0N1oXDTMzMDQwNTE1NTE0N1owIDEeMBwGA1UEAxMVaWRwMy5tYXJ0eWZvcnJl c3QuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAhDHis7lgZoph agviGBeUKWm4TNvAZtKeH8DqijCt69LuQxvcIUfOINyKZiBtwWT3fNzsRTNJFkoa U/2vkr8jOZhS3dWLI7WvCeBolF930feAGmwSR8S0cm6Ndls6QRx9O9A5Ng8nEaGS iFvddR8iDnmnQgXJ0VGnUE/6J6zqgSbPI3G58SieSwCwpTw5Aq5j3q469GaxULEw Oggls46XOsF7gb0j21RtvzGuX3h1kEIFemjw6Zan2ng7hlScVeTuZsWKv/Lz+t8f jO1McuuMPdFGA4JfPO5fHseCfkUW4nnV6rjPSw9AUXidcwzdVcTt8bj91Z+//2DM kcgglB4vxwIDAQABo3EwbzBOBgNVHREERzBFghVpZHAzLm1hcnR5Zm9ycmVzdC5j b22GLGh0dHBzOi8vaWRwMy5tYXJ0eWZvcnJlc3QuY29tL2lkcC9zaGliYm9sZXRo MB0GA1UdDgQWBBSgNBL8gHZ4tGxRXQBNAP9RHOj89TANBgkqhkiG9w0BAQUFAAOC AQEAP4KzSWGMZTxecA3akK/fiKvq1Hr1iqk2r7C2H/KK2HpUTgBJ2CHNEGzGp3Qx +nAFCTXjEwUmlHpmeiRX6mANfOTmZnKl2MD7O5apNIFS/xYdj3P5eKt7OYISGCjG 5zkXgWdGBkM+LaFiXBA2ZC/QnbSFupY2hGbO9EnoNynASwxmtwKoUElhqwZ5LsVW TYPHcvoFcwlNx8530Futj4ldlMUaNs4OuHxXIrQUg9gPFXLeKaceGD3DP/eJv7J6 9Xy/oEh87FUX0/gTRmfP9eewMBEbX0zrRxlo3VwsOcNMtHv1gLgAjfRfmbiOzBmu R4TQzLmCoAtjMz+PTtKIu8s0Wg==</span></div><div class="line"><span class="webkit-html-tag">&lt;/ds:X509Certificate&gt;</span></div></div></div></div><div class="line"><span class="webkit-html-tag">&lt;/ds:X509Data&gt;</span></div></div></div></div><div class="line"><span class="webkit-html-tag">&lt;/ds:KeyInfo&gt;</span></div></div></div></div><div class="line"><span class="webkit-html-tag">&lt;/KeyDescriptor&gt;</span></div></div></div><div class="line"><span class="webkit-html-tag">&lt;ArtifactResolutionService<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com:8443/idp/profile/SAML1/SOAP/ArtifactResolution">https://idp3.martyforrest.com:8443/idp/profile/SAML1/SOAP/ArtifactResolution</a></span>"</span><span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">index</span>="<span class="webkit-html-attribute-value">1</span>"</span>/&gt;</span></div><div class="line"><span class="webkit-html-tag">&lt;ArtifactResolutionService<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:bindings:SOAP</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com:8443/idp/profile/SAML2/SOAP/ArtifactResolution">https://idp3.martyforrest.com:8443/idp/profile/SAML2/SOAP/ArtifactResolution</a></span>"</span><span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">index</span>="<span class="webkit-html-attribute-value">2</span>"</span>/&gt;</span></div><div class="line"><span class="webkit-html-tag">&lt;NameIDFormat&gt;</span><span class="text">urn:mace:shibboleth:1.0:nameIdentifier</span><span class="webkit-html-tag">&lt;/NameIDFormat&gt;</span></div><div class="collapsible" id="collapsible7"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;NameIDFormat&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><span class="text">urn:oasis:names:tc:SAML:2.0:nameid-format:transient</span></div><div class="line"><span class="webkit-html-tag">&lt;/NameIDFormat&gt;</span></div></div></div><div class="line"><span class="webkit-html-tag">&lt;SingleSignOnService<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:mace:shibboleth:1.0:profiles:AuthnRequest</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com/idp/profile/Shibboleth/SSO">https://idp3.martyforrest.com/idp/profile/Shibboleth/SSO</a></span>"</span>/&gt;</span></div><div class="line"><span class="webkit-html-tag">&lt;SingleSignOnService<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com/idp/profile/SAML2/POST/SSO">https://idp3.martyforrest.com/idp/profile/SAML2/POST/SSO</a></span>"</span>/&gt;</span></div><div class="line"><span class="webkit-html-tag">&lt;SingleSignOnService<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com/idp/profile/SAML2/POST-SimpleSign/SSO">https://idp3.martyforrest.com/idp/profile/SAML2/POST-SimpleSign/SSO</a></span>"</span>/&gt;</span></div><div class="line"><span class="webkit-html-tag">&lt;SingleSignOnService<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com/idp/profile/SAML2/Redirect/SSO">https://idp3.martyforrest.com/idp/profile/SAML2/Redirect/SSO</a></span>"</span>/&gt;</span></div></div><div class="line"><span class="webkit-html-tag">&lt;/IDPSSODescriptor&gt;</span></div></div></div><div class="collapsible" id="collapsible8"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;AttributeAuthorityDescriptor<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">protocolSupportEnumeration</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol</span>"</span>&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible9"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;Extensions&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="line"><span class="webkit-html-tag">&lt;shibmd:Scope<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">regexp</span>="<span class="webkit-html-attribute-value">false</span>"</span>&gt;</span><span class="text"><a href="http://martyforrest.com">martyforrest.com</a></span><span class="webkit-html-tag">&lt;/shibmd:Scope&gt;</span></div></div><div class="line"><span class="webkit-html-tag">&lt;/Extensions&gt;</span></div></div></div><div class="collapsible" id="collapsible10"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;KeyDescriptor&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible11"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;ds:KeyInfo&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible12"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;ds:X509Data&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><div class="collapsible" id="collapsible13"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;ds:X509Certificate&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><span class="text">MIIDPzCCAiegAwIBAgIUI62qgIbhVfiZdfyZGFxI6rGREhYwDQYJKoZIhvcNAQEF BQAwIDEeMBwGA1UEAxMVaWRwMy5tYXJ0eWZvcnJlc3QuY29tMB4XDTEzMDQwNTE1 NTE0N1oXDTMzMDQwNTE1NTE0N1owIDEeMBwGA1UEAxMVaWRwMy5tYXJ0eWZvcnJl c3QuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAhDHis7lgZoph agviGBeUKWm4TNvAZtKeH8DqijCt69LuQxvcIUfOINyKZiBtwWT3fNzsRTNJFkoa U/2vkr8jOZhS3dWLI7WvCeBolF930feAGmwSR8S0cm6Ndls6QRx9O9A5Ng8nEaGS iFvddR8iDnmnQgXJ0VGnUE/6J6zqgSbPI3G58SieSwCwpTw5Aq5j3q469GaxULEw Oggls46XOsF7gb0j21RtvzGuX3h1kEIFemjw6Zan2ng7hlScVeTuZsWKv/Lz+t8f jO1McuuMPdFGA4JfPO5fHseCfkUW4nnV6rjPSw9AUXidcwzdVcTt8bj91Z+//2DM kcgglB4vxwIDAQABo3EwbzBOBgNVHREERzBFghVpZHAzLm1hcnR5Zm9ycmVzdC5j b22GLGh0dHBzOi8vaWRwMy5tYXJ0eWZvcnJlc3QuY29tL2lkcC9zaGliYm9sZXRo MB0GA1UdDgQWBBSgNBL8gHZ4tGxRXQBNAP9RHOj89TANBgkqhkiG9w0BAQUFAAOC AQEAP4KzSWGMZTxecA3akK/fiKvq1Hr1iqk2r7C2H/KK2HpUTgBJ2CHNEGzGp3Qx +nAFCTXjEwUmlHpmeiRX6mANfOTmZnKl2MD7O5apNIFS/xYdj3P5eKt7OYISGCjG 5zkXgWdGBkM+LaFiXBA2ZC/QnbSFupY2hGbO9EnoNynASwxmtwKoUElhqwZ5LsVW TYPHcvoFcwlNx8530Futj4ldlMUaNs4OuHxXIrQUg9gPFXLeKaceGD3DP/eJv7J6 9Xy/oEh87FUX0/gTRmfP9eewMBEbX0zrRxlo3VwsOcNMtHv1gLgAjfRfmbiOzBmu R4TQzLmCoAtjMz+PTtKIu8s0Wg==</span></div><div class="line"><span class="webkit-html-tag">&lt;/ds:X509Certificate&gt;</span></div></div></div></div><div class="line"><span class="webkit-html-tag">&lt;/ds:X509Data&gt;</span></div></div></div></div><div class="line"><span class="webkit-html-tag">&lt;/ds:KeyInfo&gt;</span></div></div></div></div><div class="line"><span class="webkit-html-tag">&lt;/KeyDescriptor&gt;</span></div></div></div><div class="line"><span class="webkit-html-tag">&lt;AttributeService<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com:8443/idp/profile/SAML1/SOAP/AttributeQuery">https://idp3.martyforrest.com:8443/idp/profile/SAML1/SOAP/AttributeQuery</a></span>"</span>/&gt;</span></div><div class="line"><span class="webkit-html-tag">&lt;AttributeService<span class="webkit-html-attribute">&nbsp;<span class="webkit-html-attribute-name">Binding</span>="<span class="webkit-html-attribute-value">urn:oasis:names:tc:SAML:2.0:bindings:SOAP</span>"</span><span class="webkit-html-attribute"><span class="webkit-html-attribute-name">Location</span>="<span class="webkit-html-attribute-value"><a href="https://idp3.martyforrest.com:8443/idp/profile/SAML2/SOAP/AttributeQuery">https://idp3.martyforrest.com:8443/idp/profile/SAML2/SOAP/AttributeQuery</a></span>"</span>/&gt;</span></div><div class="line"><span class="webkit-html-tag">&lt;NameIDFormat&gt;</span><span class="text">urn:mace:shibboleth:1.0:nameIdentifier</span><span class="webkit-html-tag">&lt;/NameIDFormat&gt;</span></div><div class="collapsible" id="collapsible14"><div class="expanded"><div class="line"><span class="button collapse-button" style="-webkit-user-select: none; cursor: pointer; display: inline-block; margin-left: -10px; width: 10px; vertical-align: bottom; background-image: -webkit-canvas(arrowDown); height: 10px; background-position: 0% 0%; background-repeat: no-repeat no-repeat;"></span><span class="webkit-html-tag">&lt;NameIDFormat&gt;</span></div><div class="collapsible-content" style="margin-left: 1em;"><span class="text">urn:oasis:names:tc:SAML:2.0:nameid-format:transient</span></div><div class="line"><span class="webkit-html-tag">&lt;/NameIDFormat&gt;</span></div></div></div></div><div class="line"><span class="webkit-html-tag">&lt;/AttributeAuthorityDescriptor&gt;</span></div></div></div></div><div class="line" style="font-family: monospace; font-size: 13px; "><span class="webkit-html-tag">&lt;/EntityDescriptor&gt;</span></div></div><div><span style="color: rgb(51, 51, 51); font-family: Arial, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 17.328125px; text-align: left; background-color: rgb(255, 255, 255); "><br></span></div><div><br></div><div><br><div><div>On 5 Apr 2013, at 14:53, Dominic Forrest &lt;<a href="mailto:dom.forrest@gmail.com">dom.forrest@gmail.com</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><br>Thankyou. &nbsp;I think I'll go back to basics on this and start agin on CentOS…. &nbsp;&nbsp;I appreciate your help but fear I may have some future questions…<br><br><br>Dom<br><br><br>On 5 Apr 2013, at 14:51, Peter Schober &lt;<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>&gt; wrote:<br><br><blockquote type="cite">I don't have an explanation yet. The snipplets you've sent so far seem<br>to be OK. The IdP seems to load the SP's metadata and vice versa. The<br>metadata for the SP looks fine.<br>So something in your deployment is off.<br><br>Note that you're running on an unsupported (by the Shibboleth project)<br>platform and did not follow the locally installed documentation.<br>I'm pretty sure Ubuntu (taking it from Debian) mentions to run the<br>shib-keygen command after installation, in which case your SP's<br>metadata would have also contained its public key. Jfyi.<br><br>* Dominic Forrest &lt;<a href="mailto:dom.forrest@gmail.com">dom.forrest@gmail.com</a>&gt; [2013-04-05 15:22]:<br><blockquote type="cite"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;metadata:MetadataProvider id="URLMD" xsi:type="metadata:FileBackedHTTPMetadataProvider"<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;metadataURL="<a href="https://sp.zzz.com/Shibboleth.sso/Metadata">https://sp.zzz.com/Shibboleth.sso/Metadata</a>"<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;backingFile="/opt/shibboleth-idp/metadata/some-metadata.xml"&gt;<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;metadata:MetadataFilter xsi:type="metadata:ChainingFilter"&gt;<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;metadata:MetadataFilter xsi:type="metadata:EntityRoleWhiteList"&gt;<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;metadata:RetainedRole&gt;samlmd:SPSSODescriptor&lt;/metadata:RetainedRole&gt;<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;/metadata:MetadataFilter&gt;<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;/metadata:MetadataFilter&gt;<br> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;/metadata:MetadataProvider&gt;<br></blockquote><br>Jfyi, the metadata generated from the SP will never contain anything<br>else but an SPSSODescriptor, so you can remove the filter (and the<br>surrounding chaining filter as it would be empty then).<br><br>Maybe the IdP is not yet actually using the changed relying-partyx.xml<br>config (requires a restart of the context or container) -- is the<br>backingFile specified above being generated properly?<br><br><blockquote type="cite">&lt;!--<br>This is example metadata only. Do *NOT* supply it as is without review,<br>and do *NOT* provide it in real time to your partners.<br>--&gt;<br></blockquote><br>Yes, so much for that.<br><br>Note that your IdP logged:<br><br> No return endpoint available for relying party <a href="https://sp.zzz.com">https://sp.zzz.com</a><br><br>but your SP config had:<br><br> entityID="<a href="https://sp.xxx.com">https://sp.xxx.com</a>"<br><br>I suppose that's just because you don't want to use RFC 2606 host<br>names in emails and you messed up the pseudonymization in your<br>examples. (The SP's metadata also had zzz.)<br><br><blockquote type="cite">What I do not understand is how this is being generated by the SP<br>however t appears I would be better saving this locally on the IDP<br>and (with help) editing as appropriate?<br></blockquote><br>Not your issue currently and will only come up later. I thought there<br>was a wiki page for that (which then should be linked from that XML<br>comment) but can't fint it atm.<br>Ignore that for now, or search the list archives.<br>-peter<br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote><br></blockquote></div><br></div></body></html>