<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br>I got that sorted and am now being challenged for credentials by the IDP :)<br><br>When I give correct credentials I now get <br>An error occurred while processing your request. Please contact your helpdesk or user ID office for assistance<br><br>This service requires cookies. Please ensure that they are enabled and try your going back to your desired resource and trying to login again.<br>Use of your browser's back button may cause specific errors that can be resolved by going back to your desired resource and trying to login again.<br>If you think you were sent here in error, please contact technical support<br>Error Message: No peer endpoint available to which to send SAML response<br><br>and<br><br>20:34:14.027 - WARN [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] - Relying party '<a href="https://sp3.martyforrest.com/shibboleth'">https://sp3.martyforrest.com/shibboleth'</a> requested the response to be returned to endpoint with ACS URL '<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST'">https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST'</a> and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however no endpoint, with that URL and using a supported binding, can be found in the relying party's metadata <br>20:34:14.027 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429] - No return endpoint available for relying party <a href="https://sp3.martyforrest.com/shibboleth">https://sp3.martyforrest.com/shibboleth</a><br>20:34:35.001 - INFO [Shibboleth-Access:74] - 20130405T193435Z|192.168.3.52|<a href="http://idp3.martyforrest.com/">idp3.martyforrest.com</a>:443|/profile/Metadata/SAML|<br><br> - which is where I was before reinstalling on Centos. <b>When I eventually get this working I'm going to write this up from start to finish in a way that works with current releases!</b><br><br>SP metadata returned from <a href="https://sp3.martyforrest.com/Shibboleth.sso/Metadata">https://sp3.martyforrest.com/Shibboleth.sso/Metadata</a> as referenced in relying_party and below - I previously posted shibboleth2.xml <div><br></div><div><br></div><div>Some further help would be appreciated and thank you again for your patience...</div><div><br></div><div><br></div><div>Dom</div><div><br></div><div><div><b> <a href="https://sp3.martyforrest.com/Shibboleth.sso/Metadata">https://sp3.martyforrest.com/Shibboleth.sso/Metadata</a></b></div><div><br></div><div><!--<br>This is example metadata only. Do *NOT* supply it as is without review,<br>and do *NOT* provide it in real time to your partners.<br> --><br><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_f1db7d762f61b1d3c0f3f8367dc03c9fe611e352" entityID="<a href="https://sp3.martyforrest.com/shibboleth">https://sp3.martyforrest.com/shibboleth</a>"><br><br> <md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"><br> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha512">http://www.w3.org/2001/04/xmlenc#sha512</a>"/><br> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#sha384">http://www.w3.org/2001/04/xmldsig-more#sha384</a>"/><br> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>"/><br> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#sha224">http://www.w3.org/2001/04/xmldsig-more#sha224</a>"/><br> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>"/><br> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512">http://www.w3.org/2001/04/xmldsig-more#rsa-sha512</a>"/><br> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384">http://www.w3.org/2001/04/xmldsig-more#rsa-sha384</a>"/><br> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>"/><br> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2009/xmldsig11#dsa-sha256">http://www.w3.org/2009/xmldsig11#dsa-sha256</a>"/><br> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>"/><br> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#dsa-sha1">http://www.w3.org/2000/09/xmldsig#dsa-sha1</a>"/><br> </md:Extensions><br><br> <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"><br> <md:Extensions><br> <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/Login">https://sp3.martyforrest.com/Shibboleth.sso/Login</a>"/><br> <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/Login">https://sp3.martyforrest.com/Shibboleth.sso/Login</a>" index="1"/><br> </md:Extensions><br> <md:KeyDescriptor><br> <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"><br> <ds:KeyName><a href="http://sp3.martyforrest.com/">sp3.martyforrest.com</a></ds:KeyName><br> <ds:X509Data><br> <ds:X509SubjectName>CN=<a href="http://sp3.martyforrest.com/">sp3.martyforrest.com</a></ds:X509SubjectName><br> <ds:X509Certificate>MIIDAzCCAeugAwIBAgIJAKCXl8N+F2wVMA0GCSqGSIb3DQEBBQUAMB8xHTAbBgNV<br>BAMTFHNwMy5tYXJ0eWZvcnJlc3QuY29tMB4XDTEzMDQwNTE2NTcxN1oXDTIzMDQw<br>MzE2NTcxN1owHzEdMBsGA1UEAxMUc3AzLm1hcnR5Zm9ycmVzdC5jb20wggEiMA0G<br>CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCjlJ/00b6E9ZomKkDnBFMbfH/4NMUI<br>Ah7VGlGpH6/s/yqlFzcNZ+7oKpihxJ069E6AQD6fLxWGHZBpP3/olx/mCacskWbd<br>NT6EZAhENN9+ntW5BVqLKZ33MN/jtrDT/HfKUuCP4ZmQa6XSSmK8lWfTd/ZPQVe5<br>NvDEEcZQqk2sD1nero601e7ZiN3yq0nwDtTRLvNoxDPojy9v9RZJIXTyskpy1y0D<br>IVRuAQT7GtXoIk8kP+h9SKOYeGI9khDp9dOthhaHzO7tRYOo0mMefpBUdqlb3+fc<br>MzuUunXIzwNAvZYnwbzVSA3Kk55Fi4f9BfealSBy5DboObJZ1cKA0Yn7AgMBAAGj<br>QjBAMB8GA1UdEQQYMBaCFHNwMy5tYXJ0eWZvcnJlc3QuY29tMB0GA1UdDgQWBBTF<br>zYVY5QYyK6Ph0blhM7xdku/dvzANBgkqhkiG9w0BAQUFAAOCAQEAa9CM5FdTM/5e<br>zNcfvc1LytaJ3nele729te5tvkalPSzCgEIvVguf5y4OLCZRuL07y9tL5AKqZNWn<br>vSqGNFL/0pkzveKEDt/sliSPumU+MhYryuv2WzAclkYOOBNqeM3OhBY5i2JL4GrP<br>xLKeljCyvuytAEgOOFkz2OfILOaiqO/QLvieA0AY/upfIBlurjzH4s+XKlf+KiEm<br>33FE2EZNlwL7uB61ie9IYnqOnGDj7ek0PeARHbTj871QB4gQL/bmm1nLO+zv9Dn7<br>Yy3M7clMCSsVwFxppUI5rHykP5Vxm4ejnmp7z08dupszpUnQcokXL4FtkL7j/8yL<br>tM2IYXCc4A==<br></ds:X509Certificate><br> </ds:X509Data><br> </ds:KeyInfo><br> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes128-cbc">http://www.w3.org/2001/04/xmlenc#aes128-cbc</a>"/><br> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes192-cbc">http://www.w3.org/2001/04/xmlenc#aes192-cbc</a>"/><br> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes256-cbc">http://www.w3.org/2001/04/xmlenc#aes256-cbc</a>"/><br> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#tripledes-cbc">http://www.w3.org/2001/04/xmlenc#tripledes-cbc</a>"/><br> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2009/xmlenc11#rsa-oaep">http://www.w3.org/2009/xmlenc11#rsa-oaep</a>"/><br> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p">http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p</a>"/><br> </md:KeyDescriptor><br> <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/Artifact/SOAP">https://sp3.martyforrest.com/Shibboleth.sso/Artifact/SOAP</a>" index="1"/><br> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SLO/SOAP">https://sp3.martyforrest.com/Shibboleth.sso/SLO/SOAP</a>"/><br> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SLO/Redirect">https://sp3.martyforrest.com/Shibboleth.sso/SLO/Redirect</a>"/><br> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SLO/POST">https://sp3.martyforrest.com/Shibboleth.sso/SLO/POST</a>"/><br> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SLO/Artifact">https://sp3.martyforrest.com/Shibboleth.sso/SLO/Artifact</a>"/><br> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST">https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST</a>" index="1"/><br> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST-SimpleSign">https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST-SimpleSign</a>" index="2"/><br> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/Artifact">https://sp3.martyforrest.com/Shibboleth.sso/SAML2/Artifact</a>" index="3"/><br> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/ECP">https://sp3.martyforrest.com/Shibboleth.sso/SAML2/ECP</a>" index="4"/><br> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML/POST">https://sp3.martyforrest.com/Shibboleth.sso/SAML/POST</a>" index="5"/><br> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML/Artifact">https://sp3.martyforrest.com/Shibboleth.sso/SAML/Artifact</a>" index="6"/><br> </md:SPSSODescriptor><br><br></md:EntityDescriptor></div><div><br></div><div><br></div></div><div><div>On 5 Apr 2013, at 20:34, "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">On 4/5/13 3:23 PM, "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br><br><blockquote type="cite">Whatever config you're using is enforcing a validUntil requirement. Take<br>the filter out that's requiring that, that's the easiest fix for simple<br>testing.<br><br>I don't know where that came from, unless it's in the defaults.<br></blockquote><br>Indeed it is. I don't think the SP defaults at this point are compatible<br>with the IdP's metadata generated at install time. That metadata is<br>static, so I'm sure it has no validUntil time set in the file. It's never<br>been noted before, surprisingly.<br><br>-- Scott<br><br><br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></body></html>