<html><body><div style="color:#000; background-color:#fff; font-family:times new roman, new york, times, serif;font-size:12pt"><div><span>Hi Scott,</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal;"><span>Appreciate your response.</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal;"><span>I will talk to my IDP , appears something is wrong at their end.</span></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal;"><span>But is there a reason why you suggested not to use a certificate from entruch but to you the one provided during shib installation ?</span></div><div><br></div> <div style="font-family: 'times
new roman', 'new york', times, serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <hr size="1"> <font size="2" face="Arial"> <b><span style="font-weight:bold;">From:</span></b> "Cantor, Scott" <cantor.2@osu.edu><br> <b><span style="font-weight: bold;">To:</span></b> Shib Users <users@shibboleth.net> <br> <b><span style="font-weight: bold;">Sent:</span></b> Thursday, July 11, 2013 11:03 AM<br> <b><span style="font-weight: bold;">Subject:</span></b> RE: Issue with URL re-direct after IDP authentication - signing
        Assertion<br> </font> </div> <div class="y_msg_container"><br>> The next step proposed by my IDP was for me to send my certificate so the<br>> Assertion can be signed and encrypted.<br>> I sent my certificate bought from entrust to my IDP, I added the new<br>> certificate path and certificate key path to by shibboleth2.xml.<br><br>Do not do that. Use the self-signed certificate created during installation.<br><br>> then as suggested by my idp i added the below to my shibboleth2.xml<br>> signing="true" encryption="true"<br><br>None of that has anything to do with them signing or encrypting anything, that causes you to sign requests. Unless you need that, don't.<br><br>> now what happens is when i login to my site url -<br>> <a href="https://dev.myapp.com/testsite," target="_blank">https://dev.myapp.com/testsite, </a>i get redirected to my IDP and after i login<br>> i see the below error page and the saml redirect doesnt
happen.<br><br>That does not appear to be the SP, or Shibboleth, but their IdP.<br><br>> is the a reason why this doesnt sign at the first attempt. so i need to<br>> configure anything else.<br><br>You'd have to ask them, it's their software. Unless that location bar is lying, because that's not a Shibboleth SP URL, it looks like a SSO endpoint in an IdP to me.<br><br>-- Scott<br><br><br><br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br></div> </div> </div> </div></body></html>