<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" id="owaParaStyle"></style>
</head>
<body fpstyle="1" ocsi="0">
<div style="direction: ltr;font-family: Tahoma;color: #000000;font-size: 10pt;">
<div style="direction:ltr; font-family:Tahoma; color:#000000; font-size:10pt">Not hearing anything back from UC Trust after filing my paperwork, I have asked around and found out there is an undocumented procedure where I have to try to identify a Shibboleth
 sponsor on each campus where I need attribute release who can work with the campus IdP to get us set up.
<div><br>
</div>
<div>My first campus sponsor reports that they can access one of my applications, but not the other. &nbsp;For the application where they cannot log in, they report an error &quot;no peer endpoint available to which to send SAML response&quot; and I see messages such as&nbsp;</div>
<div><br>
</div>
<div>shib_handler: Invalid HTTP method (GET).</div>
<div>shib_handler: remoted message returned an error: Unable to establish security of incoming assertion.</div>
<div>shib_handler: Unable to establish security of incoming assertion.</div>
<div>
<div>shib_handler: remoted message returned an error: Request missing SAMLart query string or form parameter.</div>
<div>shib_handler: Request missing SAMLart query string or form parameter.</div>
</div>
<div><br>
</div>
<div>in .../log/http/native.log that occured around the time he tried to log in.</div>
<div><br>
</div>
<div>there are also entires in transaction.log around the time he tried to log in</div>
<div><br>
</div>
<div>
<div>2013-08-22 10:24:57 INFO Shibboleth-TRANSACTION [36924]: New session (ID: ) with (applicationId: default) for principal from (IdP: none) at (ClientAddress: 198.108.5.62) with (NameIdentifier: none) using (Protocol: urn:oasis:names:tc:SAML:1.1:protocol)
 from (AssertionID: )</div>
<div>2013-08-22 10:24:57 INFO Shibboleth-TRANSACTION [36924]: Cached the following attributes with session (ID: ) for (applicationId: default) {</div>
<div>2013-08-22 10:24:57 INFO Shibboleth-TRANSACTION [36924]: }</div>
</div>
<div><br>
</div>
<div>Can someone please advise me what I can check on my end that might be different between the two services? &nbsp;</div>
<div><br>
</div>
<div>I noticed one difference re: SAML2 and SAML1 in the attribute-map.xml -- but I made these files exaclty the same, restarted the shibd and the http -- the the sponsor reports that he is getting the same error. &nbsp;</div>
<div><br>
</div>
<div>When the sponsor got the error the second time around, nothing was logged in native.log nor transaction.log, but his attempt was logged in ssl_access.</div>
<div><br>
</div>
<div>Or, what should I ask my sponsor to ask his IdP with regard to debugging this issue?</div>
<div><br>
</div>
<div>Thanks for your help -- Brian</div>
</div>
</div>
</body>
</html>