<html>
  <head>
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    Hello there,<br>
    &nbsp;&nbsp;&nbsp;&nbsp; I have an issue I cannot seem to fix and I would appreciate any
    help you can provide.&nbsp;&nbsp; I am using Shibboleth on a CentOS system
    (the SP) and testshib.org as the IDP.&nbsp; Here is basically what
    happens<br>
    a)&nbsp;&nbsp; &nbsp;Try to access &#8216;secure&#8217; page<br>
    b)&nbsp;&nbsp; &nbsp;Presented with login &#8211; login as myself<br>
    c)&nbsp;&nbsp; &nbsp;Get error &#8220;No Peer Endpoint&#8221;<br>
    <br>
    I am at a loss at what more I can do to debug this.&nbsp;&nbsp; It appears the
    IDP cannot find the system name in the metadata.&nbsp; I have reloaded
    the metadata a couple of times, and recopied Shibboleth2.xml,
    restart shib and&nbsp; http, etc.&nbsp; (Though the last few times the
    Shibboleth2.xml has not had any changes in it.)<br>
    <br>
    Any help or suggestions about how to troubleshoot that you can
    provide would be appreciated. <br>
    <br>
    <i>Low Priority:&nbsp; I also have a question about how to set this up so
      I can use different IDP&#8217;s for different URL (/secure/dir1/* goes
      to IDP-A, /secure/dir2/* goes to IDP-B).&nbsp;&nbsp; If you could recommend
      a good web source, white paper, book, etc.&nbsp; that discusses this, I
      would appreciate it.</i><br>
    Thanks,<br>
    George Boney<br>
    <br>
    <b>Detailed Flow and description.</b><br>
    Try to access URL&nbsp;&nbsp; &#8220;george.rmtcentral.net/secure/hello.cgi&#8221;<br>
    &nbsp;(BTW, you can access &#8220;george.rmtcentral.net/unsecure/hello.cgi&#8221;
    just to see the expected result)<br>
    It asks for a login (myself/myself) and then presents a page that
    says:<br>
    -------------------------------------------------------------<br>
    Something horrible happened. &#8230;<br>
    Error Message: No peer endpoint available to which to send SAML
    response<br>
    ---------------------------------------------------------------<br>
    <b>The log file says</b>:<br>
    &#8230;<br>
    20:26:39.906 - DEBUG
    [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:170]

    - Incoming request contains a login context and indicates principal
    was authenticated, processing second leg of request<br>
    20:26:39.907 - DEBUG
    [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128]

    - Looking up relying party configuration for <a
      class="moz-txt-link-freetext"
      href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a><br>
    20:26:39.907 - DEBUG
    [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134]

    - No custom relying party configuration found for <a
      class="moz-txt-link-freetext"
      href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>,
    looking up configuration based on metadata groups.<br>
    20:26:39.908 - DEBUG
    [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157]

    - No custom or group-based relying party configuration found for <a
      class="moz-txt-link-freetext"
      href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>.
    Using default relying party configuration.<br>
    20:26:39.909 - WARN
    [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] -
    Relying party '<a class="moz-txt-link-freetext"
      href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>'
    requested the response to be returned to endpoint with ACS URL '<a
      class="moz-txt-link-freetext"
      href="http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST</a>'&nbsp;
    and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however
    no endpoint, with that URL and using a supported binding,&nbsp; can be
    found in the relying party's metadata<br>
    20:26:39.909 - ERROR
    [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429]

    - No return endpoint available for relying party <a
      class="moz-txt-link-freetext"
      href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a><br>
    <b>Metadata</b><br>
    The metadata file (&#8220;Meda_George_Data.&#8221;&nbsp; Attached) shows<br>
    &lt;!--This is example metadata only. Do *NOT* supply it as is
    without review, and do *NOT* provide it in real time to your
    partners.--&gt;<br>
    &lt;md:EntityDescriptor
    xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
    xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui"
    ID="_19d9edf1851c00adc2a634793a1f9e536282b96c" entityID=<a
      class="moz-txt-link-rfc2396E"
      href="https://george.rmtcentral.net/shibboleth">"https://george.rmtcentral.net/shibboleth"</a>&gt;<br>
    &nbsp; &lt;md:Extensions xmlns:<br>
    &nbsp;&#8230;.&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;<br>
    &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;md:SingleLogoutService
    Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
    Location=<a class="moz-txt-link-rfc2396E"
      href="https://george.rmtcentral.net/Shibboleth.sso/SLO/Redirect">"https://george.rmtcentral.net/Shibboleth.sso/SLO/Redirect"</a>/&gt;<br>
    &nbsp;&nbsp;&nbsp; &lt;md:SingleLogoutService
    Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location=<a
      class="moz-txt-link-rfc2396E"
      href="https://george.rmtcentral.net/Shibboleth.sso/SLO/POST">"https://george.rmtcentral.net/Shibboleth.sso/SLO/POST"</a>/&gt;<br>
    &nbsp;&nbsp;&nbsp; &lt;md:SingleLogoutService
    Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"
    Location=<a class="moz-txt-link-rfc2396E"
      href="https://george.rmtcentral.net/Shibboleth.sso/SLO/Artifact">"https://george.rmtcentral.net/Shibboleth.sso/SLO/Artifact"</a>/&gt;<br>
    &nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService
    Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location=<a
      class="moz-txt-link-rfc2396E"
      href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">"https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST"</a>
    index="1"/&gt;<br>
    &nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService
    Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
    Location=<a class="moz-txt-link-rfc2396E"
href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST-SimpleSign">"https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST-SimpleSign"</a>
    index="2"/&gt;<br>
    &#8230;<br>
    &nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService
    Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location=<a
      class="moz-txt-link-rfc2396E"
      href="https://george.rmtcentral.net/Shibboleth.sso/SAML/Artifact">"https://george.rmtcentral.net/Shibboleth.sso/SAML/Artifact"</a>
    index="6"/&gt;<br>
    &nbsp; &lt;/md:SPSSODescriptor&gt;<br>
    &lt;/md:EntityDescriptor&gt;<br>
    <br>
  </body>
</html>