<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br>I got that sorted and am now being challenged for credentials by the IDP :)<br><br>When I give correct credentials I now get&nbsp;<br>An error occurred while processing your request. Please contact your helpdesk or user ID office for assistance<br><br>This service requires cookies. Please ensure that they are enabled and try your going back to your desired resource and trying to login again.<br>Use of your browser's back button may cause specific errors that can be resolved by going back to your desired resource and trying to login again.<br>If you think you were sent here in error, please contact technical support<br>Error Message: No peer endpoint available to which to send SAML response<br><br>and<br><br>20:34:14.027 - WARN [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] - Relying party '<a href="https://sp3.martyforrest.com/shibboleth'">https://sp3.martyforrest.com/shibboleth'</a>&nbsp;requested the response to be returned to endpoint with ACS URL&nbsp;'<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST'">https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST'</a>&nbsp;&nbsp;and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however no endpoint, with that URL and using a supported binding, &nbsp;can be found in the relying party's metadata&nbsp;<br>20:34:14.027 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429] - No return endpoint available for relying party&nbsp;<a href="https://sp3.martyforrest.com/shibboleth">https://sp3.martyforrest.com/shibboleth</a><br>20:34:35.001 - INFO [Shibboleth-Access:74] - 20130405T193435Z|192.168.3.52|<a href="http://idp3.martyforrest.com/">idp3.martyforrest.com</a>:443|/profile/Metadata/SAML|<br><br>&nbsp;- which is where I was before reinstalling on Centos.&nbsp;<b>When I eventually get this working I'm going to write this up from start to finish in a way that works with current releases!</b><br><br>SP metadata returned from&nbsp;<a href="https://sp3.martyforrest.com/Shibboleth.sso/Metadata">https://sp3.martyforrest.com/Shibboleth.sso/Metadata</a>&nbsp;as referenced in relying_party and &nbsp;below - I previously posted shibboleth2.xml&nbsp;<div><br></div><div><br></div><div>Some further help would be appreciated and thank you again for your patience...</div><div><br></div><div><br></div><div>Dom</div><div><br></div><div><div><b>&nbsp;<a href="https://sp3.martyforrest.com/Shibboleth.sso/Metadata">https://sp3.martyforrest.com/Shibboleth.sso/Metadata</a></b></div><div><br></div><div>&lt;!--<br>This is example metadata only. Do *NOT* supply it as is without review,<br>and do *NOT* provide it in real time to your partners.<br>&nbsp;--&gt;<br>&lt;md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_f1db7d762f61b1d3c0f3f8367dc03c9fe611e352" entityID="<a href="https://sp3.martyforrest.com/shibboleth">https://sp3.martyforrest.com/shibboleth</a>"&gt;<br><br>&nbsp; &lt;md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"&gt;<br>&nbsp; &nbsp; &lt;alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha512">http://www.w3.org/2001/04/xmlenc#sha512</a>"/&gt;<br>&nbsp; &nbsp; &lt;alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#sha384">http://www.w3.org/2001/04/xmldsig-more#sha384</a>"/&gt;<br>&nbsp; &nbsp; &lt;alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>"/&gt;<br>&nbsp; &nbsp; &lt;alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#sha224">http://www.w3.org/2001/04/xmldsig-more#sha224</a>"/&gt;<br>&nbsp; &nbsp; &lt;alg:DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>"/&gt;<br>&nbsp; &nbsp; &lt;alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512">http://www.w3.org/2001/04/xmldsig-more#rsa-sha512</a>"/&gt;<br>&nbsp; &nbsp; &lt;alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384">http://www.w3.org/2001/04/xmldsig-more#rsa-sha384</a>"/&gt;<br>&nbsp; &nbsp; &lt;alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>"/&gt;<br>&nbsp; &nbsp; &lt;alg:SigningMethod Algorithm="<a href="http://www.w3.org/2009/xmldsig11#dsa-sha256">http://www.w3.org/2009/xmldsig11#dsa-sha256</a>"/&gt;<br>&nbsp; &nbsp; &lt;alg:SigningMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>"/&gt;<br>&nbsp; &nbsp; &lt;alg:SigningMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#dsa-sha1">http://www.w3.org/2000/09/xmldsig#dsa-sha1</a>"/&gt;<br>&nbsp; &lt;/md:Extensions&gt;<br><br>&nbsp; &lt;md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"&gt;<br>&nbsp; &nbsp; &lt;md:Extensions&gt;<br>&nbsp; &nbsp; &nbsp; &lt;init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/Login">https://sp3.martyforrest.com/Shibboleth.sso/Login</a>"/&gt;<br>&nbsp; &nbsp; &nbsp; &lt;idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/Login">https://sp3.martyforrest.com/Shibboleth.sso/Login</a>" index="1"/&gt;<br>&nbsp; &nbsp; &lt;/md:Extensions&gt;<br>&nbsp; &nbsp; &lt;md:KeyDescriptor&gt;<br>&nbsp; &nbsp; &nbsp; &lt;ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:KeyName&gt;<a href="http://sp3.martyforrest.com/">sp3.martyforrest.com</a>&lt;/ds:KeyName&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:X509Data&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:X509SubjectName&gt;CN=<a href="http://sp3.martyforrest.com/">sp3.martyforrest.com</a>&lt;/ds:X509SubjectName&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &lt;ds:X509Certificate&gt;MIIDAzCCAeugAwIBAgIJAKCXl8N+F2wVMA0GCSqGSIb3DQEBBQUAMB8xHTAbBgNV<br>BAMTFHNwMy5tYXJ0eWZvcnJlc3QuY29tMB4XDTEzMDQwNTE2NTcxN1oXDTIzMDQw<br>MzE2NTcxN1owHzEdMBsGA1UEAxMUc3AzLm1hcnR5Zm9ycmVzdC5jb20wggEiMA0G<br>CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCjlJ/00b6E9ZomKkDnBFMbfH/4NMUI<br>Ah7VGlGpH6/s/yqlFzcNZ+7oKpihxJ069E6AQD6fLxWGHZBpP3/olx/mCacskWbd<br>NT6EZAhENN9+ntW5BVqLKZ33MN/jtrDT/HfKUuCP4ZmQa6XSSmK8lWfTd/ZPQVe5<br>NvDEEcZQqk2sD1nero601e7ZiN3yq0nwDtTRLvNoxDPojy9v9RZJIXTyskpy1y0D<br>IVRuAQT7GtXoIk8kP+h9SKOYeGI9khDp9dOthhaHzO7tRYOo0mMefpBUdqlb3+fc<br>MzuUunXIzwNAvZYnwbzVSA3Kk55Fi4f9BfealSBy5DboObJZ1cKA0Yn7AgMBAAGj<br>QjBAMB8GA1UdEQQYMBaCFHNwMy5tYXJ0eWZvcnJlc3QuY29tMB0GA1UdDgQWBBTF<br>zYVY5QYyK6Ph0blhM7xdku/dvzANBgkqhkiG9w0BAQUFAAOCAQEAa9CM5FdTM/5e<br>zNcfvc1LytaJ3nele729te5tvkalPSzCgEIvVguf5y4OLCZRuL07y9tL5AKqZNWn<br>vSqGNFL/0pkzveKEDt/sliSPumU+MhYryuv2WzAclkYOOBNqeM3OhBY5i2JL4GrP<br>xLKeljCyvuytAEgOOFkz2OfILOaiqO/QLvieA0AY/upfIBlurjzH4s+XKlf+KiEm<br>33FE2EZNlwL7uB61ie9IYnqOnGDj7ek0PeARHbTj871QB4gQL/bmm1nLO+zv9Dn7<br>Yy3M7clMCSsVwFxppUI5rHykP5Vxm4ejnmp7z08dupszpUnQcokXL4FtkL7j/8yL<br>tM2IYXCc4A==<br>&lt;/ds:X509Certificate&gt;<br>&nbsp; &nbsp; &nbsp; &nbsp; &lt;/ds:X509Data&gt;<br>&nbsp; &nbsp; &nbsp; &lt;/ds:KeyInfo&gt;<br>&nbsp; &nbsp; &nbsp; &lt;md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes128-cbc">http://www.w3.org/2001/04/xmlenc#aes128-cbc</a>"/&gt;<br>&nbsp; &nbsp; &nbsp; &lt;md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes192-cbc">http://www.w3.org/2001/04/xmlenc#aes192-cbc</a>"/&gt;<br>&nbsp; &nbsp; &nbsp; &lt;md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes256-cbc">http://www.w3.org/2001/04/xmlenc#aes256-cbc</a>"/&gt;<br>&nbsp; &nbsp; &nbsp; &lt;md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#tripledes-cbc">http://www.w3.org/2001/04/xmlenc#tripledes-cbc</a>"/&gt;<br>&nbsp; &nbsp; &nbsp; &lt;md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2009/xmlenc11#rsa-oaep">http://www.w3.org/2009/xmlenc11#rsa-oaep</a>"/&gt;<br>&nbsp; &nbsp; &nbsp; &lt;md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p">http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p</a>"/&gt;<br>&nbsp; &nbsp; &lt;/md:KeyDescriptor&gt;<br>&nbsp; &nbsp; &lt;md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/Artifact/SOAP">https://sp3.martyforrest.com/Shibboleth.sso/Artifact/SOAP</a>" index="1"/&gt;<br>&nbsp; &nbsp; &lt;md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SLO/SOAP">https://sp3.martyforrest.com/Shibboleth.sso/SLO/SOAP</a>"/&gt;<br>&nbsp; &nbsp; &lt;md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SLO/Redirect">https://sp3.martyforrest.com/Shibboleth.sso/SLO/Redirect</a>"/&gt;<br>&nbsp; &nbsp; &lt;md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SLO/POST">https://sp3.martyforrest.com/Shibboleth.sso/SLO/POST</a>"/&gt;<br>&nbsp; &nbsp; &lt;md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SLO/Artifact">https://sp3.martyforrest.com/Shibboleth.sso/SLO/Artifact</a>"/&gt;<br>&nbsp; &nbsp; &lt;md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST">https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST</a>" index="1"/&gt;<br>&nbsp; &nbsp; &lt;md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST-SimpleSign">https://sp3.martyforrest.com/Shibboleth.sso/SAML2/POST-SimpleSign</a>" index="2"/&gt;<br>&nbsp; &nbsp; &lt;md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/Artifact">https://sp3.martyforrest.com/Shibboleth.sso/SAML2/Artifact</a>" index="3"/&gt;<br>&nbsp; &nbsp; &lt;md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML2/ECP">https://sp3.martyforrest.com/Shibboleth.sso/SAML2/ECP</a>" index="4"/&gt;<br>&nbsp; &nbsp; &lt;md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML/POST">https://sp3.martyforrest.com/Shibboleth.sso/SAML/POST</a>" index="5"/&gt;<br>&nbsp; &nbsp; &lt;md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="<a href="https://sp3.martyforrest.com/Shibboleth.sso/SAML/Artifact">https://sp3.martyforrest.com/Shibboleth.sso/SAML/Artifact</a>" index="6"/&gt;<br>&nbsp; &lt;/md:SPSSODescriptor&gt;<br><br>&lt;/md:EntityDescriptor&gt;</div><div><br></div><div><br></div></div><div><div>On 5 Apr 2013, at 20:34, "Cantor, Scott" &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">On 4/5/13 3:23 PM, "Cantor, Scott" &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; wrote:<br><br><blockquote type="cite">Whatever config you're using is enforcing a validUntil requirement. Take<br>the filter out that's requiring that, that's the easiest fix for simple<br>testing.<br><br>I don't know where that came from, unless it's in the defaults.<br></blockquote><br>Indeed it is. I don't think the SP defaults at this point are compatible<br>with the IdP's metadata generated at install time. That metadata is<br>static, so I'm sure it has no validUntil time set in the file. It's never<br>been noted before, surprisingly.<br><br>-- Scott<br><br><br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></body></html>