<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" id="owaParaStyle"></style>
</head>
<body fpstyle="1" ocsi="0">
<div style="direction: ltr;font-family: Tahoma;color: #000000;font-size: 10pt;">
<div style="direction:ltr; font-family:Tahoma; color:#000000; font-size:10pt">Not hearing anything back from UC Trust after filing my paperwork, I have asked around and found out there is an undocumented procedure where I have to try to identify a Shibboleth
sponsor on each campus where I need attribute release who can work with the campus IdP to get us set up.
<div><br>
</div>
<div>My first campus sponsor reports that they can access one of my applications, but not the other. For the application where they cannot log in, they report an error "no peer endpoint available to which to send SAML response" and I see messages such as </div>
<div><br>
</div>
<div>shib_handler: Invalid HTTP method (GET).</div>
<div>shib_handler: remoted message returned an error: Unable to establish security of incoming assertion.</div>
<div>shib_handler: Unable to establish security of incoming assertion.</div>
<div>
<div>shib_handler: remoted message returned an error: Request missing SAMLart query string or form parameter.</div>
<div>shib_handler: Request missing SAMLart query string or form parameter.</div>
</div>
<div><br>
</div>
<div>in .../log/http/native.log that occured around the time he tried to log in.</div>
<div><br>
</div>
<div>there are also entires in transaction.log around the time he tried to log in</div>
<div><br>
</div>
<div>
<div>2013-08-22 10:24:57 INFO Shibboleth-TRANSACTION [36924]: New session (ID: ) with (applicationId: default) for principal from (IdP: none) at (ClientAddress: 198.108.5.62) with (NameIdentifier: none) using (Protocol: urn:oasis:names:tc:SAML:1.1:protocol)
from (AssertionID: )</div>
<div>2013-08-22 10:24:57 INFO Shibboleth-TRANSACTION [36924]: Cached the following attributes with session (ID: ) for (applicationId: default) {</div>
<div>2013-08-22 10:24:57 INFO Shibboleth-TRANSACTION [36924]: }</div>
</div>
<div><br>
</div>
<div>Can someone please advise me what I can check on my end that might be different between the two services? </div>
<div><br>
</div>
<div>I noticed one difference re: SAML2 and SAML1 in the attribute-map.xml -- but I made these files exaclty the same, restarted the shibd and the http -- the the sponsor reports that he is getting the same error. </div>
<div><br>
</div>
<div>When the sponsor got the error the second time around, nothing was logged in native.log nor transaction.log, but his attempt was logged in ssl_access.</div>
<div><br>
</div>
<div>Or, what should I ask my sponsor to ask his IdP with regard to debugging this issue?</div>
<div><br>
</div>
<div>Thanks for your help -- Brian</div>
</div>
</div>
</body>
</html>