<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Note that the endpoint listed in those log entries for where the response is supposed to be sent is:<div><br></div><div>&nbsp;&nbsp;<a class="moz-txt-link-freetext" href="http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST</a></div><div><br></div><div>but the endpoint corresponding to the SAML2 Post binding in the metadata entry is:</div><div><br></div><div>&nbsp;&nbsp;<a class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST</a></div><div><br></div><div>Note the difference -- one is http, one is https. The endpoint that is requested in the authn request does *not* match a registered endpoint in your metadata.</div><div><br><div><div>On May 17, 2013, at 8:19 PM, George Boney wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">
  
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
  
  <div text="#000000" bgcolor="#FFFFFF">
    Hello there,<br>
    &nbsp;&nbsp;&nbsp;&nbsp; I have an issue I cannot seem to fix and I would appreciate any
    help you can provide.&nbsp;&nbsp; I am using Shibboleth on a CentOS system
    (the SP) and <a href="http://testshib.org">testshib.org</a> as the IDP.&nbsp; Here is basically what
    happens<br>
    a)&nbsp;&nbsp; &nbsp;Try to access ‘secure’ page<br>
    b)&nbsp;&nbsp; &nbsp;Presented with login – login as myself<br>
    c)&nbsp;&nbsp; &nbsp;Get error “No Peer Endpoint”<br>
    <br>
    I am at a loss at what more I can do to debug this.&nbsp;&nbsp; It appears the
    IDP cannot find the system name in the metadata.&nbsp; I have reloaded
    the metadata a couple of times, and recopied Shibboleth2.xml,
    restart shib and&nbsp; http, etc.&nbsp; (Though the last few times the
    Shibboleth2.xml has not had any changes in it.)<br>
    <br>
    Any help or suggestions about how to troubleshoot that you can
    provide would be appreciated. <br>
    <br>
    <i>Low Priority:&nbsp; I also have a question about how to set this up so
      I can use different IDP’s for different URL (/secure/dir1/* goes
      to IDP-A, /secure/dir2/* goes to IDP-B).&nbsp;&nbsp; If you could recommend
      a good web source, white paper, book, etc.&nbsp; that discusses this, I
      would appreciate it.</i><br>
    Thanks,<br>
    George Boney<br>
    <br>
    <b>Detailed Flow and description.</b><br>
    Try to access URL&nbsp;&nbsp; “george.rmtcentral.net/secure/hello.cgi”<br>
    &nbsp;(BTW, you can access “george.rmtcentral.net/unsecure/hello.cgi”
    just to see the expected result)<br>
    It asks for a login (myself/myself) and then presents a page that
    says:<br>
    -------------------------------------------------------------<br>
    Something horrible happened. …<br>
    Error Message: No peer endpoint available to which to send SAML
    response<br>
    ---------------------------------------------------------------<br>
    <b>The log file says</b>:<br>
    …<br>
    20:26:39.906 - DEBUG
    [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:170]

    - Incoming request contains a login context and indicates principal
    was authenticated, processing second leg of request<br>
    20:26:39.907 - DEBUG
    [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128]

    - Looking up relying party configuration for <a class="moz-txt-link-freetext" href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a><br>
    20:26:39.907 - DEBUG
    [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134]

    - No custom relying party configuration found for <a class="moz-txt-link-freetext" href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>,
    looking up configuration based on metadata groups.<br>
    20:26:39.908 - DEBUG
    [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157]

    - No custom or group-based relying party configuration found for <a class="moz-txt-link-freetext" href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>.
    Using default relying party configuration.<br>
    20:26:39.909 - WARN
    [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] -
    Relying party '<a class="moz-txt-link-freetext" href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>'
    requested the response to be returned to endpoint with ACS URL '<a class="moz-txt-link-freetext" href="http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST</a>'&nbsp;
    and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however
    no endpoint, with that URL and using a supported binding,&nbsp; can be
    found in the relying party's metadata<br>
    20:26:39.909 - ERROR
    [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429]

    - No return endpoint available for relying party <a class="moz-txt-link-freetext" href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a><br>
    <b>Metadata</b><br>
    The metadata file (“Meda_George_Data.”&nbsp; Attached) shows<br>
    &lt;!--This is example metadata only. Do *NOT* supply it as is
    without review, and do *NOT* provide it in real time to your
    partners.--&gt;<br>
    &lt;md:EntityDescriptor
    xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
    xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui"
    ID="_19d9edf1851c00adc2a634793a1f9e536282b96c" entityID=<a class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/shibboleth">"https://george.rmtcentral.net/shibboleth"</a>&gt;<br>
    &nbsp; &lt;md:Extensions xmlns:<br>
    &nbsp;….&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;<br>
    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;md:SingleLogoutService
    Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
    Location=<a class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SLO/Redirect">"https://george.rmtcentral.net/Shibboleth.sso/SLO/Redirect"</a>/&gt;<br>
    &nbsp;&nbsp;&nbsp; &lt;md:SingleLogoutService
    Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location=<a class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SLO/POST">"https://george.rmtcentral.net/Shibboleth.sso/SLO/POST"</a>/&gt;<br>
    &nbsp;&nbsp;&nbsp; &lt;md:SingleLogoutService
    Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"
    Location=<a class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SLO/Artifact">"https://george.rmtcentral.net/Shibboleth.sso/SLO/Artifact"</a>/&gt;<br>
    &nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService
    Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location=<a class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">"https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST"</a>
    index="1"/&gt;<br>
    &nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService
    Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
    Location=<a class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST-SimpleSign">"https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST-SimpleSign"</a>
    index="2"/&gt;<br>
    …<br>
    &nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService
    Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location=<a class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SAML/Artifact">"https://george.rmtcentral.net/Shibboleth.sso/SAML/Artifact"</a>
    index="6"/&gt;<br>
    &nbsp; &lt;/md:SPSSODescriptor&gt;<br>
    &lt;/md:EntityDescriptor&gt;<br>
    <br>
  </div>

<span>&lt;Meda_George_Data.html&gt;</span>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br><div>
<span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><br>--<br>Michael A. Grady<br>Senior IAM Consultant, Unicon, Inc.</div></div></span></div></span></span>
</div>

<br></div></body></html>