<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
OK, we have now built a new IDP on a separate box. We are again at the point where the login windows is displayed and is able to authenticate. On what should be the return path from successful authentication, however, we are still getting this error:
<div><br>
</div>
<div>
<div>ERROR</div>
<div><br>
</div>
<div>An error occurred while processing your request. Please contact your helpdesk or user ID office for assistance.</div>
<div><br>
</div>
<div>This service requires cookies. Please ensure that they are enabled and try your going back to your desired resource and trying to login again.</div>
<div><br>
</div>
<div>Use of your browser's back button may cause specific errors that can be resolved by going back to your desired resource and trying to login again.</div>
<div><br>
</div>
<div>If you think you were sent here in error, please contact technical support</div>
<div>Error Message: No peer endpoint available to which to send SAML response</div>
<div><br>
</div>
<div>In idp-process.log I see:</div>
<div>
<div>12:23:24.245 - INFO [Shibboleth-Access:73] - 20131114T092324Z|207.162.245.59|idpt.qatar-med.cornell.edu:443|/profile/SAML2/Redirect/SSO|</div>
<div>12:23:30.802 - INFO [Shibboleth-Access:73] - 20131114T092330Z|207.162.245.59|idpt.qatar-med.cornell.edu:443|/profile/SAML2/Redirect/SSO|</div>
<div>12:23:30.805 - WARN [org.opensaml.saml2.binding.AuthnResponseEndpointSelector:206] - Relying party 'https://unixadmin.qatar-med.cornell.edu/secure' requested the response to be returned to endpoint with ACS URL 'http://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST'
and binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' however no endpoint, with that URL and using a supported binding, can be found in the relying party's metadata </div>
<div>12:23:30.806 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:447] - No return endpoint available for relying party
<a href="https://unixadmin.qatar-med.cornell.edu/secure">https://unixadmin.qatar-med.cornell.edu/secure</a></div>
</div>
<div><br>
</div>
<div>In shibd_warn.log I see:</div>
<div>
<div>2013-11-14 12:15:19 ERROR Shibboleth.ArtifactResolution.SAML2 [1]: error while processing request: Invalid content type for SOAP message.</div>
<div>2013-11-14 12:15:30 WARN OpenSAML.MessageDecoder.SAML2SOAP [2]: ignoring incorrect content type ()</div>
<div>2013-11-14 12:15:38 WARN OpenSAML.MessageDecoder.SAML2SOAP [7]: ignoring incorrect content type ()</div>
<div>2013-11-14 12:19:04 WARN OpenSAML.MessageDecoder.SAML2ECP [8]: ignoring incorrect content type ()</div>
</div>
<div><br>
</div>
<div>I have an inkling that this probably relates to the SP and IDP not able to agree on how to handshake the success but I'm not able to figure out how to resolve this.</div>
<div><br>
</div>
<div>Thanks!</div>
<div><br>
</div>
<div>Sam</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div>
<div>On Nov 5, 2013, at 3:29 PM, Peter Schober wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div>* Sam Agnew <<a href="mailto:saa2012@qatar-med.cornell.edu">saa2012@qatar-med.cornell.edu</a>> [2013-11-05 13:02]:<br>
<blockquote type="cite">When authentication succeeds, however, I now get an error about the return path:<br>
</blockquote>
<blockquote type="cite"><br>
</blockquote>
<blockquote type="cite">Error Message: No peer endpoint available to which to send SAML response<br>
</blockquote>
[...]<br>
<blockquote type="cite">Looking in idp-process.log I see:<br>
</blockquote>
<blockquote type="cite">14:27:58.505 - WARN [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:81] - SPSSODescriptor role metadata for entityID 'https://unixadmin.qatar-med.cornell.edu/idp/shibboleth' could not be resolved<br>
</blockquote>
<br>
What is the SP's entityID? It cannot share the same entityID as the<br>
IdP (if you want to remain sane), so if it's<br>
"<a href="https://unixadmin.qatar-med.cornell.edu/idp/shibboleth">https://unixadmin.qatar-med.cornell.edu/idp/shibboleth</a>" (note the<br>
"idp" hint in the entityID) give the SP its own, seperate entityID.<br>
<br>
Then give the IdP SAML metadata describing the SP.<br>
-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><br>
</div>
</blockquote>
</div>
<br>
<div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; "><br class="Apple-interchange-newline">
--</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Sam Agnew</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
System Administrator</div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">IT Department</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Weill Cornell Medical College in Qatar</font></div>
<div style="font-family: Helvetica; font-size: 12px; "><br class="webkit-block-placeholder">
</div>
<br class="Apple-interchange-newline">
</div>
<br>
</div>
</body>
</html>