<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
George,
<div><br>
</div>
<div>You're probably starting the authentication process by access <a href="http://george.rmtcentral.net/">
http://george.rmtcentral.net/</a> instead of <a href="https://george.rmtcentral.net">
https://george.rmtcentral.net</a>.</div>
<div><br>
</div>
<div>Your metadata file is uploaded and trusted and fine. &nbsp;The problem is somewhere else.</div>
<div><br>
</div>
<div>
<div>[testshib-user-metadata]$ grep rmtcentral *</div>
<div>Meda_George_Data:&lt;md:EntityDescriptor xmlns:md=&quot;urn:oasis:names:tc:SAML:2.0:metadata&quot; xmlns:mdui=&quot;urn:oasis:names:tc:SAML:metadata:ui&quot; ID=&quot;_19d9edf1851c00adc2a634793a1f9e536282b96c&quot; entityID=&quot;<a href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>&quot;&gt;</div>
</div>
<div>
<div>...</div>
<div>Meda_George_Data: &nbsp; &nbsp;&lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Location=&quot;<a href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST</a>&quot; index=&quot;1&quot;/&gt;</div>
</div>
<div><br>
</div>
<div>If you intend to have users access your site using cookies over http://, you can add that endpoint to your metadata and re-upload it, but this generally makes sniffing and replaying cookies/sessions easy.</div>
<div><br>
</div>
<div>Thanks,</div>
<div>Nate.</div>
<div><br>
<div>
<div>On May 18, 2013, at 16:51 , George Boney wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div text="#000000" bgcolor="#FFFFFF">Yes, I noticed that.&nbsp; But (and I may not understand how this works) the metadata file says &quot;use https&quot;, but the reason it sends it to &quot;http&quot; is &quot;No custom or group-based relying party configuration found&quot;(from log).&nbsp;&nbsp; I
 interpret this to mean it can't find &quot;george..&quot; in Metadata, so it used the default (&quot;Using default relying party configuration&quot; http) which doesn't work.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp; I want it to use what is in the Meta file I uploaded (Plus I don't understand why it does not find the data I uploaded it --- or is that what a normal log file looks like?)&nbsp; Could I have an error in the Metadata file?<br>
<br>
Thanks,<br>
George<br>
<div class="moz-cite-prefix">On 5/17/2013 10:41 PM, Michael A Grady wrote:<br>
</div>
<blockquote cite="mid:57871934-0709-49A5-931A-34DCCA5AE10E@unicon.net" type="cite">
Note that the endpoint listed in those log entries for where the response is supposed to be sent is:
<div><br>
</div>
<div>&nbsp;&nbsp;<a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST</a></div>
<div><br>
</div>
<div>but the endpoint corresponding to the SAML2 Post binding in the metadata entry is:</div>
<div><br>
</div>
<div>&nbsp;&nbsp;<a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST</a></div>
<div><br>
</div>
<div>Note the difference -- one is http, one is https. The endpoint that is requested in the authn request does *not* match a registered endpoint in your metadata.</div>
<div><br>
<div>
<div>On May 17, 2013, at 8:19 PM, George Boney wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div text="#000000" bgcolor="#FFFFFF">Hello there,<br>
&nbsp;&nbsp;&nbsp;&nbsp; I have an issue I cannot seem to fix and I would appreciate any help you can provide.&nbsp;&nbsp; I am using Shibboleth on a CentOS system (the SP) and
<a moz-do-not-send="true" href="http://testshib.org/">testshib.org</a> as the IDP.&nbsp; Here is basically what happens<br>
a)&nbsp;&nbsp; &nbsp;Try to access ‘secure’ page<br>
b)&nbsp;&nbsp; &nbsp;Presented with login – login as myself<br>
c)&nbsp;&nbsp; &nbsp;Get error “No Peer Endpoint”<br>
<br>
I am at a loss at what more I can do to debug this.&nbsp;&nbsp; It appears the IDP cannot find the system name in the metadata.&nbsp; I have reloaded the metadata a couple of times, and recopied Shibboleth2.xml, restart shib and&nbsp; http, etc.&nbsp; (Though the last few times the
 Shibboleth2.xml has not had any changes in it.)<br>
<br>
Any help or suggestions about how to troubleshoot that you can provide would be appreciated.
<br>
<br>
<i>Low Priority:&nbsp; I also have a question about how to set this up so I can use different IDP’s for different URL (/secure/dir1/* goes to IDP-A, /secure/dir2/* goes to IDP-B).&nbsp;&nbsp; If you could recommend a good web source, white paper, book, etc.&nbsp; that discusses
 this, I would appreciate it.</i><br>
Thanks,<br>
George Boney<br>
<br>
<b>Detailed Flow and description.</b><br>
Try to access URL&nbsp;&nbsp; “george.rmtcentral.net/secure/hello.cgi”<br>
&nbsp;(BTW, you can access “george.rmtcentral.net/unsecure/hello.cgi” just to see the expected result)<br>
It asks for a login (myself/myself) and then presents a page that says:<br>
-------------------------------------------------------------<br>
Something horrible happened. …<br>
Error Message: No peer endpoint available to which to send SAML response<br>
---------------------------------------------------------------<br>
<b>The log file says</b>:<br>
…<br>
20:26:39.906 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:170] - Incoming request contains a login context and indicates principal was authenticated, processing second leg of request<br>
20:26:39.907 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128] - Looking up relying party configuration for
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://george.rmtcentral.net/shibboleth">
https://george.rmtcentral.net/shibboleth</a><br>
20:26:39.907 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134] - No custom relying party configuration found for
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://george.rmtcentral.net/shibboleth">
https://george.rmtcentral.net/shibboleth</a>, looking up configuration based on metadata groups.<br>
20:26:39.908 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157] - No custom or group-based relying party configuration found for
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://george.rmtcentral.net/shibboleth">
https://george.rmtcentral.net/shibboleth</a>. Using default relying party configuration.<br>
20:26:39.909 - WARN [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] - Relying party '<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://george.rmtcentral.net/shibboleth">https://george.rmtcentral.net/shibboleth</a>' requested
 the response to be returned to endpoint with ACS URL '<a moz-do-not-send="true" class="moz-txt-link-freetext" href="http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">http://george.rmtcentral.net/Shibboleth.sso/SAML2/POST</a>'&nbsp; and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST'
 however no endpoint, with that URL and using a supported binding,&nbsp; can be found in the relying party's metadata<br>
20:26:39.909 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429] - No return endpoint available for relying party
<a moz-do-not-send="true" class="moz-txt-link-freetext" href="https://george.rmtcentral.net/shibboleth">
https://george.rmtcentral.net/shibboleth</a><br>
<b>Metadata</b><br>
The metadata file (“Meda_George_Data.”&nbsp; Attached) shows<br>
&lt;!--This is example metadata only. Do *NOT* supply it as is without review, and do *NOT* provide it in real time to your partners.--&gt;<br>
&lt;md:EntityDescriptor xmlns:md=&quot;urn:oasis:names:tc:SAML:2.0:metadata&quot; xmlns:mdui=&quot;urn:oasis:names:tc:SAML:metadata:ui&quot; ID=&quot;_19d9edf1851c00adc2a634793a1f9e536282b96c&quot; entityID=<a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/shibboleth">&quot;https://george.rmtcentral.net/shibboleth&quot;</a>&gt;<br>
&nbsp; &lt;md:Extensions xmlns:<br>
&nbsp;….&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;md:SingleLogoutService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect&quot; Location=<a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SLO/Redirect">&quot;https://george.rmtcentral.net/Shibboleth.sso/SLO/Redirect&quot;</a>/&gt;<br>
&nbsp;&nbsp;&nbsp; &lt;md:SingleLogoutService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Location=<a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SLO/POST">&quot;https://george.rmtcentral.net/Shibboleth.sso/SLO/POST&quot;</a>/&gt;<br>
&nbsp;&nbsp;&nbsp; &lt;md:SingleLogoutService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact&quot; Location=<a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SLO/Artifact">&quot;https://george.rmtcentral.net/Shibboleth.sso/SLO/Artifact&quot;</a>/&gt;<br>
&nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Location=<a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST">&quot;https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST&quot;</a>
 index=&quot;1&quot;/&gt;<br>
&nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign&quot; Location=<a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST-SimpleSign">&quot;https://george.rmtcentral.net/Shibboleth.sso/SAML2/POST-SimpleSign&quot;</a>
 index=&quot;2&quot;/&gt;<br>
…<br>
&nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:1.0:profiles:artifact-01&quot; Location=<a moz-do-not-send="true" class="moz-txt-link-rfc2396E" href="https://george.rmtcentral.net/Shibboleth.sso/SAML/Artifact">&quot;https://george.rmtcentral.net/Shibboleth.sso/SAML/Artifact&quot;</a>
 index=&quot;6&quot;/&gt;<br>
&nbsp; &lt;/md:SPSSODescriptor&gt;<br>
&lt;/md:EntityDescriptor&gt;<br>
<br>
</div>
<span>&lt;Meda_George_Data.html&gt;</span>--<br>
To unsubscribe from this list send an email to <a moz-do-not-send="true" href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></blockquote>
</div>
<br>
<div>
<div style="word-wrap: break-word; -webkit-nbsp-mode:
                space; -webkit-line-break: after-white-space; ">
<div style="word-wrap: break-word; -webkit-nbsp-mode:
                    space; -webkit-line-break: after-white-space; ">
<div><br>
--<br>
Michael A. Grady<br>
Senior IAM Consultant, Unicon, Inc.</div>
</div>
</div>
</div>
<br>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset> <br>
<pre wrap="">--
To unsubscribe from this list send an email to <a class="moz-txt-link-abbreviated" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></pre>
</blockquote>
<br>
</div>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></blockquote>
</div>
<br>
</div>
</body>
</html>