<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
Peter,
<div><br>
</div>
<div>Thank you for your help!</div>
<div><br>
<div>
<div>On Nov 5, 2013, at 11:59 AM, Peter Schober wrote:</div>
<br class="Apple-interchange-newline">
</div>
<div><br>
<blockquote type="cite">
<div><br>
<blockquote type="cite">2013-11-05 10:19:59 ERROR XMLTooling.libcurl.InputStream : error<br>
</blockquote>
<blockquote type="cite">while fetching <a href="https://unixadmin.qatar-med.cornell.edu:">
https://unixadmin.qatar-med.cornell.edu:</a> (22) The<br>
</blockquote>
<blockquote type="cite">requested URL returned error: 403 Forbidden<br>
</blockquote>
<br>
If that is the entityID (or the URL for metadata) of the IdP then it<br>
does not match the above entityID which ends in "/idp/shibboleth".<br>
</div>
</blockquote>
<div><br>
</div>
OK. I found that indeed the URL was wrong in /etc/shibboleth/shibboleth2.xml. I corrected the URL based on the example to:</div>
<div><a href="https://unixadmin.qatar-med.cornell.edu/idp/profile/Metadata/SAML">https://unixadmin.qatar-med.cornell.edu/idp/profile/Metadata/SAML</a></div>
<div><br>
</div>
<div>This got me to the login window for the IDP. We are authenticating via LDAP. I managed to get the CA trusted via the Java keystore.<br>
</div>
<div>When authentication succeeds, however, I now get an error about the return path:</div>
<div><br>
</div>
<div><strong>Error Message: No peer endpoint available to which to send SAML response</strong></div>
<div><br>
</div>
<div>Looking in shibd_warn.logs I see:</div>
<div>
<div>2013-11-05 14:23:17 ERROR XMLTooling.libcurl.InputStream : error while fetching
<a href="https://unixadmin.qatar-med.cornell.edu/idp/profile/Metadata/SAML:">https://unixadmin.qatar-med.cornell.edu/idp/profile/Metadata/SAML:</a> (22) The requested URL returned error: 404 Not Found</div>
<div>2013-11-05 14:23:17 ERROR XMLTooling.ParserPool : fatal error on line 0, column 0, message: internal error in NetAccessor</div>
<div>2013-11-05 14:23:17 ERROR OpenSAML.MetadataProvider.XML : error while loading resource (<a href="https://unixadmin.qatar-med.cornell.edu/idp/profile/Metadata/SAML">https://unixadmin.qatar-med.cornell.edu/idp/profile/Metadata/SAML</a>): XML error(s) during
parsing, check log for specifics</div>
<div>2013-11-05 14:23:17 WARN OpenSAML.MetadataProvider.XML : adjusted reload interval to 600 seconds</div>
<div>2013-11-05 14:23:17 WARN OpenSAML.MetadataProvider.XML : trying backup file, exception loading remote resource: XML error(s) during parsing, check log for specifics</div>
<div>2013-11-05 14:27:15 WARN Shibboleth.Application : insecure cookieProps setting, set to "https" for SSL/TLS-only usage</div>
<div>2013-11-05 14:27:15 WARN Shibboleth.Application : handlerSSL should be enabled for SSL/TLS-enabled web sites</div>
<div><br>
</div>
<div>Although actually visiting the URL (<a href="https://unixadmin.qatar-med.cornell.edu/idp/profile/Metadata/SAM">https://unixadmin.qatar-med.cornell.edu/idp/profile/Metadata/SAM</a>) does show me XML output in a web browser.</div>
<div><br>
</div>
<div>Looking in idp-process.log I see:</div>
<div>
<div>14:27:58.505 - WARN [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:81] - SPSSODescriptor role metadata for entityID 'https://unixadmin.qatar-med.cornell.edu/idp/shibboleth' could not be resolved</div>
<div>14:29:03.613 - INFO [Shibboleth-Access:73] - 20131105T112903Z|207.162.244.209|unixadmin.qatar-med.cornell.edu:443|/profile/SAML2/Redirect/SSO|</div>
<div>14:29:03.620 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:447] - No return endpoint available for relying party
<a href="https://unixadmin.qatar-med.cornell.edu/idp/shibboleth">https://unixadmin.qatar-med.cornell.edu/idp/shibboleth</a></div>
<div>14:30:18.031 - INFO [Shibboleth-Access:73] - 20131105T113018Z|207.162.244.209|unixadmin.qatar-med.cornell.edu:443|/profile/SAML2/Redirect/SSO|</div>
<div>14:30:18.035 - WARN [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:81] - SPSSODescriptor role metadata for entityID 'https://unixadmin.qatar-med.cornell.edu/idp/shibboleth' could not be resolved</div>
<div>14:30:28.671 - INFO [Shibboleth-Access:73] - 20131105T113028Z|207.162.244.209|unixadmin.qatar-med.cornell.edu:443|/profile/SAML2/Redirect/SSO|</div>
<div>14:30:28.672 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:447] - No return endpoint available for relying party
<a href="https://unixadmin.qatar-med.cornell.edu/idp/shibboleth">https://unixadmin.qatar-med.cornell.edu/idp/shibboleth</a></div>
<div>14:42:49.400 - INFO [Shibboleth-Access:73] - 20131105T114249Z|207.162.244.209|unixadmin.qatar-med.cornell.edu:443|/profile/Metadata/SAML|</div>
<div>14:53:46.252 - INFO [Shibboleth-Access:73] - 20131105T115346Z|207.162.244.209|unixadmin.qatar-med.cornell.edu:443|/profile/Metadata/SAML|</div>
<div><br>
</div>
<div>I'm not sure how to resolve this.</div>
<div><br>
</div>
<div>Thanks!</div>
<div><br>
</div>
<div>Sam</div>
<div><br>
</div>
<div><br>
</div>
</div>
</div>
<div><br>
</div>
<div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; "><br class="Apple-interchange-newline">
--</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Sam Agnew</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
System Administrator</div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">IT Department</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Weill Cornell Medical College in Qatar</font></div>
<div style="font-family: Helvetica; font-size: 12px; "><br class="webkit-block-placeholder">
</div>
<br class="Apple-interchange-newline">
</div>
<br>
</div>
</body>
</html>