<html>
<head>
<meta http-equiv="content-type" content="text/html;
charset=ISO-8859-1">
</head>
<body text="#000000" bgcolor="#FFFFFF">
Hello there,<br>
I have an issue I cannot seem to fix and I would appreciate any
help you can provide. I am using Shibboleth on a CentOS system
(the SP) and testshib.org as the IDP. Here is basically what
happens<br>
a) Try to access ‘secure’ page<br>
b) Presented with login – login as myself<br>
c) Get error “No Peer Endpoint”<br>
<br>
I am at a loss at what more I can do to debug this. It appears the
IDP cannot find the system name in the metadata. I have reloaded
the metadata a couple of times, and recopied Shibboleth2.xml,
restart shib and http, etc. (Though the last few times the
Shibboleth2.xml has not had any changes in it.)<br>
<br>
Any help or suggestions about how to troubleshoot that you can
provide would be appreciated. <br>
<br>
<i>Low Priority: I also have a question about how to set this up so
I can use different IDP’s for different URL (/secure/dir1/* goes
to IDP-A, /secure/dir2/* goes to IDP-B). If you could recommend
a good web source, white paper, book, etc. that discusses this, I
would appreciate it.</i><br>
Thanks,<br>
George Boney<br>
<br>
<b>Detailed Flow and description.</b><br>
Try to access URL “george.rmtcentral.net/secure/hello.cgi”<br>
(BTW, you can access “george.rmtcentral.net/unsecure/hello.cgi”
just to see the expected result)<br>
It asks for a login (myself/myself) and then presents a page that
says:<br>
-------------------------------------------------------------<br>
Something horrible happened. …<br>
Error Message: No peer endpoint available to which to send SAML
response<br>
---------------------------------------------------------------<br>
<b>The log file says</b>:<br>
…<br>
20:26:39.906 - DEBUG
[edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:170]
- Incoming request contains a login context and indicates principal
was authenticated, processing second leg of request<br>
20:26:39.907 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128]
- Looking up relying party configuration for <a
class="moz-txt-link-freetext"
href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a><br>
20:26:39.907 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134]
- No custom relying party configuration found for <a
class="moz-txt-link-freetext"
href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>,
looking up configuration based on metadata groups.<br>
20:26:39.908 - DEBUG
[edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157]
- No custom or group-based relying party configuration found for <a
class="moz-txt-link-freetext"
href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>.
Using default relying party configuration.<br>
20:26:39.909 - WARN
[org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] -
Relying party '<a class="moz-txt-link-freetext"
href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>'
requested the response to be returned to endpoint with ACS URL '<a
class="moz-txt-link-freetext"
href="http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST</a>'
and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however
no endpoint, with that URL and using a supported binding, can be
found in the relying party's metadata<br>
20:26:39.909 - ERROR
[edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429]
- No return endpoint available for relying party <a
class="moz-txt-link-freetext"
href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a><br>
<b>Metadata</b><br>
The metadata file (“Meda_George_Data.” Attached) shows<br>
<!--This is example metadata only. Do *NOT* supply it as is
without review, and do *NOT* provide it in real time to your
partners.--><br>
<md:EntityDescriptor
xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui"
ID="_19d9edf1851c00adc2a634793a1f9e536282b96c" entityID=<a
class="moz-txt-link-rfc2396E"
href="https://george.rmtcentral.net/shibboleth">"https://george.rmtcentral.net/shibboleth"</a>><br>
<md:Extensions xmlns:<br>
…. <br>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"
Location=<a class="moz-txt-link-rfc2396E"
href="https://george.rmtcentral.net/Shibboleth.sso/SLO/Redirect">"https://george.rmtcentral.net/Shibboleth.sso/SLO/Redirect"</a>/><br>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location=<a
class="moz-txt-link-rfc2396E"
href="https://george.rmtcentral.net/Shibboleth.sso/SLO/POST">"https://george.rmtcentral.net/Shibboleth.sso/SLO/POST"</a>/><br>
<md:SingleLogoutService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"
Location=<a class="moz-txt-link-rfc2396E"
href="https://george.rmtcentral.net/Shibboleth.sso/SLO/Artifact">"https://george.rmtcentral.net/Shibboleth.sso/SLO/Artifact"</a>/><br>
<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location=<a
class="moz-txt-link-rfc2396E"
href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">"https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST"</a>
index="1"/><br>
<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"
Location=<a class="moz-txt-link-rfc2396E"
href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST-SimpleSign">"https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST-SimpleSign"</a>
index="2"/><br>
…<br>
<md:AssertionConsumerService
Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location=<a
class="moz-txt-link-rfc2396E"
href="https://george.rmtcentral.net/Shibboleth.sso/SAML/Artifact">"https://george.rmtcentral.net/Shibboleth.sso/SAML/Artifact"</a>
index="6"/><br>
</md:SPSSODescriptor><br>
</md:EntityDescriptor><br>
<br>
</body>
</html>