<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
That is extremely helpful!
<div><br>
</div>
<div>So, I have done the testshib tests and my IDP gets a green light.</div>
<div><br>
</div>
<div>On SP I am getting the following:</div>
<div><br>
</div>
<div>opensaml::FatalProfileException at (<a href="https://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST">https://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST</a>)</div>
<div><br>
</div>
<div>In the SP log I am seeing:</div>
<div><br>
</div>
<div>
<div>2013-12-03 10:46:24 DEBUG OpenSAML.MessageDecoder.SAML2 [2]: message from (<a href="https://idp.testshib.org/idp/shibboleth">https://idp.testshib.org/idp/shibboleth</a>)</div>
<div>2013-12-03 10:46:24 DEBUG OpenSAML.MessageDecoder.SAML2 [2]: searching metadata for message issuer...</div>
<div>2013-12-03 10:46:24 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2]: evaluating message flow policy (replay checking on, expiration 60)</div>
<div>2013-12-03 10:46:24 DEBUG XMLTooling.StorageService [2]: inserted record (_230cbdfe7380299798cda4d07ddda6f3) in context (MessageFlow) with expiration (1386058644)</div>
<div>2013-12-03 10:46:24 DEBUG Shibboleth.SSO.SAML2 [2]: processing message against SAML 2.0 SSO profile</div>
<div>2013-12-03 10:46:24 DEBUG XMLTooling.CredentialCriteria [2]: key algorithm didn't match ('AES' != 'RSA')</div>
<div>2013-12-03 10:46:24 DEBUG Shibboleth.SSO.SAML2 [2]: decrypted Assertion: &lt;saml2:Assertion xmlns:saml2=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot; ID=&quot;_8d729efc980cff99911f402d42a02721&quot; IssueInstant=&quot;2013-12-03T07:46:24.057Z&quot; Version=&quot;2.0&quot; xmlns:xs=&quot;<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>&quot;&gt;&lt;saml2:Issuer
 Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:entity&quot;&gt;https://idp.testshib.org/idp/shibboleth&lt;/saml2:Issuer&gt;&lt;ds:Signature xmlns:ds=&quot;<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>&quot;&gt;&lt;ds:SignedInfo&gt;&lt;ds:CanonicalizationMethod
 Algorithm=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot;/&gt;&lt;ds:SignatureMethod Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>&quot;/&gt;&lt;ds:Reference URI=&quot;#_8d729efc980cff99911f402d42a02721&quot;&gt;&lt;ds:Transforms&gt;&lt;ds:Transform
 Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>&quot;/&gt;&lt;ds:Transform Algorithm=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot;&gt;&lt;ec:InclusiveNamespaces
 xmlns:ec=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot; PrefixList=&quot;xs&quot;/&gt;&lt;/ds:Transform&gt;&lt;/ds:Transforms&gt;&lt;ds:DigestMethod Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>&quot;/&gt;&lt;ds:DigestValue&gt;YInKw0cfaUenzAqZZyJz0fhxVTM=&lt;/ds:DigestValue&gt;&lt;/ds:Reference&gt;&lt;/ds:SignedInfo&gt;&lt;ds:SignatureValue&gt;MBESUrz8So35/yL59ScxB4VuWwsxkoQAp5XHrUtvj6/JuiCbGYiuo2yN1zumNGOmdG5LF3FWBRkeJET1oNwJ6ciQHyv/Gk2nl7HB7WKeWs78OiJZ5EABlO1h5rRYxJYIwqnFloZVuyjL3t4rUVwHO8M0tkpjbtgOxhY/Qv0HszXaUNuVivcwU5RCtqC8M5LEYJwFv0ANvArx8EL6AE8nTFpLA26wAvcFw&#43;nP7uj8Kfee01Kr28XFHFJxqrzWWS&#43;ZapPyeFV/k6JIgKC6hbca2gd7hKBRdBsfP31r2WGe/PVcwAJLTNu6afQYMa0kr1jqGkIbT35My5c5JYRVRcdmxw==&lt;/ds:SignatureValue&gt;&lt;ds:KeyInfo&gt;&lt;ds:X509Data&gt;&lt;ds:X509Certificate&gt;MIIEDjCCAvagAwIBAgIBADANBgkqhkiG9w0BAQUFADBnMQswCQYDVQQGEwJVUzEVMBMGA1UECBMM</div>
<div>UGVubnN5bHZhbmlhMRMwEQYDVQQHEwpQaXR0c2J1cmdoMREwDwYDVQQKEwhUZXN0U2hpYjEZMBcG</div>
<div>A1UEAxMQaWRwLnRlc3RzaGliLm9yZzAeFw0wNjA4MzAyMTEyMjVaFw0xNjA4MjcyMTEyMjVaMGcx</div>
<div>CzAJBgNVBAYTAlVTMRUwEwYDVQQIEwxQZW5uc3lsdmFuaWExEzARBgNVBAcTClBpdHRzYnVyZ2gx</div>
<div>ETAPBgNVBAoTCFRlc3RTaGliMRkwFwYDVQQDExBpZHAudGVzdHNoaWIub3JnMIIBIjANBgkqhkiG</div>
<div>9w0BAQEFAAOCAQ8AMIIBCgKCAQEArYkCGuTmJp9eAOSGHwRJo1SNatB5ZOKqDM9ysg7CyVTDClcp</div>
<div>u93gSP10nH4gkCZOlnESNgttg0r&#43;MqL8tfJC6ybddEFB3YBo8PZajKSe3OQ01Ow3yT4I&#43;Wdg1tsT</div>
<div>pSge9gEz7SrC07EkYmHuPtd71CHiUaCWDv&#43;xVfUQX0aTNPFmDixzUjoYzbGDrtAyCqA8f9CN2txI</div>
<div>fJnpHE6q6CmKcoLADS4UrNPlhHSzd614kR/JYiks0K4kbRqCQF0Dv0P5Di&#43;rEfefC6glV8ysC8dB</div>
<div>5/9nb0yh/ojRuJGmgMWHgWk6h0ihjihqiu4jACovUZ7vVOCgSE5Ipn7OIwqd93zp2wIDAQABo4HE</div>
<div>MIHBMB0GA1UdDgQWBBSsBQ869nh83KqZr5jArr4/7b&#43;QazCBkQYDVR0jBIGJMIGGgBSsBQ869nh8</div>
<div>3KqZr5jArr4/7b&#43;Qa6FrpGkwZzELMAkGA1UEBhMCVVMxFTATBgNVBAgTDFBlbm5zeWx2YW5pYTET</div>
<div>MBEGA1UEBxMKUGl0dHNidXJnaDERMA8GA1UEChMIVGVzdFNoaWIxGTAXBgNVBAMTEGlkcC50ZXN0</div>
<div>c2hpYi5vcmeCAQAwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQUFAAOCAQEAjR29PhrCbk8qLN5M</div>
<div>FfSVk98t3CT9jHZoYxd8QMRLI4j7iYQxXiGJTT1FXs1nd4Rha9un&#43;LqTfeMMYqISdDDI6tv8iNpk</div>
<div>OAvZZUosVkUo93pv1T0RPz35hcHHYq2yee59HJOco2bFlcsH8JBXRSRrJ3Q7Eut&#43;z9uo80JdGNJ4</div>
<div>/SJy5UorZ8KazGj16lfJhOBXldgrhppQBb0Nq6HKHguqmwRfJ&#43;WkxemZXzhediAjGeka8nz8Jjwx</div>
<div>pUjAiSWYKLtJhGEaTqCYxCCX2Dw&#43;dOTqUzHOZ7WKv4JXPK5G/Uhr8K/qhmFT2nIQi538n6rVYLeW</div>
<div>j8Bbnl&#43;ev0peYzxFyF5sQA==&lt;/ds:X509Certificate&gt;&lt;/ds:X509Data&gt;&lt;/ds:KeyInfo&gt;&lt;/ds:Signature&gt;&lt;saml2:Subject&gt;&lt;saml2:NameID Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:transient&quot; NameQualifier=&quot;<a href="https://idp.testshib.org/idp/shibboleth">https://idp.testshib.org/idp/shibboleth</a>&quot;
 SPNameQualifier=&quot;<a href="https://unixadmin.qatar-med.cornell.edu/shibboleth">https://unixadmin.qatar-med.cornell.edu/shibboleth</a>&quot;&gt;_7ea49dcb356fa855acffc5834717de64&lt;/saml2:NameID&gt;&lt;saml2:SubjectConfirmation Method=&quot;urn:oasis:names:tc:SAML:2.0:cm:bearer&quot;&gt;&lt;saml2:SubjectConfirmationData
 Address=&quot;207.162.244.209&quot; InResponseTo=&quot;_aedca934600d6c7dd42616f5678525da&quot; NotOnOrAfter=&quot;2013-12-03T07:51:24.057Z&quot; Recipient=&quot;<a href="https://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST">https://unixadmin.qatar-med.cornell.edu/Shibboleth.sso/SAML2/POST</a>&quot;/&gt;&lt;/saml2:SubjectConfirmation&gt;&lt;/saml2:Subject&gt;&lt;saml2:Conditions
 NotBefore=&quot;2013-12-03T07:46:24.057Z&quot; NotOnOrAfter=&quot;2013-12-03T07:51:24.057Z&quot;&gt;&lt;saml2:AudienceRestriction&gt;&lt;saml2:Audience&gt;https://unixadmin.qatar-med.cornell.edu/shibboleth&lt;/saml2:Audience&gt;&lt;/saml2:AudienceRestriction&gt;&lt;/saml2:Conditions&gt;&lt;saml2:AuthnStatement
 AuthnInstant=&quot;2013-12-03T07:46:23.769Z&quot; SessionIndex=&quot;_a5532e9a1436b7db665cb9c7ab512745&quot;&gt;&lt;saml2:SubjectLocality Address=&quot;207.162.244.209&quot;/&gt;&lt;saml2:AuthnContext&gt;&lt;saml2:AuthnContextClassRef&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport&lt;/saml2:AuthnContextClassRef&gt;&lt;/saml2:AuthnContext&gt;&lt;/saml2:AuthnStatement&gt;&lt;saml2:AttributeStatement&gt;&lt;saml2:Attribute
 FriendlyName=&quot;uid&quot; Name=&quot;urn:oid:0.9.2342.19200300.100.1.1&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot; xsi:type=&quot;xs:string&quot;&gt;alterego&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute
 FriendlyName=&quot;eduPersonAffiliation&quot; Name=&quot;urn:oid:1.3.6.1.4.1.5923.1.1.1.1&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot;
 xsi:type=&quot;xs:string&quot;&gt;Member&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;eduPersonPrincipalName&quot; Name=&quot;urn:oid:1.3.6.1.4.1.5923.1.1.1.6&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot;
 xsi:type=&quot;xs:string&quot;&gt;alterego@testshib.org&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;sn&quot; Name=&quot;urn:oid:2.5.4.4&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot;
 xsi:type=&quot;xs:string&quot;&gt;Ego&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;eduPersonScopedAffiliation&quot; Name=&quot;urn:oid:1.3.6.1.4.1.5923.1.1.1.9&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot;
 xsi:type=&quot;xs:string&quot;&gt;Member@testshib.org&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;givenName&quot; Name=&quot;urn:oid:2.5.4.42&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot;
 xsi:type=&quot;xs:string&quot;&gt;Alter&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;eduPersonEntitlement&quot; Name=&quot;urn:oid:1.3.6.1.4.1.5923.1.1.1.7&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot;
 xsi:type=&quot;xs:string&quot;&gt;urn:mace:dir:entitlement:common-lib-terms&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;cn&quot; Name=&quot;urn:oid:2.5.4.3&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot;
 xsi:type=&quot;xs:string&quot;&gt;Alter Ego&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute FriendlyName=&quot;eduPersonTargetedID&quot; Name=&quot;urn:oid:1.3.6.1.4.1.5923.1.1.1.10&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue&gt;&lt;saml2:NameID
 Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:persistent&quot; NameQualifier=&quot;<a href="https://idp.testshib.org/idp/shibboleth">https://idp.testshib.org/idp/shibboleth</a>&quot; SPNameQualifier=&quot;<a href="https://unixadmin.qatar-med.cornell.edu/shibboleth">https://unixadmin.qatar-med.cornell.edu/shibboleth</a>&quot;&gt;9j6nnTVtlPrxSShOqLFw4ZR6mKs=&lt;/saml2:NameID&gt;&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;saml2:Attribute
 FriendlyName=&quot;telephoneNumber&quot; Name=&quot;urn:oid:2.5.4.20&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:uri&quot;&gt;&lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot; xsi:type=&quot;xs:string&quot;&gt;555-5555&lt;/saml2:AttributeValue&gt;&lt;/saml2:Attribute&gt;&lt;/saml2:AttributeStatement&gt;&lt;/saml2:Assertion&gt;</div>
<div>2013-12-03 10:46:24 DEBUG Shibboleth.SSO.SAML2 [2]: extracting issuer from SAML 2.0 assertion</div>
<div>2013-12-03 10:46:24 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [2]: evaluating message flow policy (replay checking on, expiration 60)</div>
<div>2013-12-03 10:46:24 DEBUG XMLTooling.StorageService [2]: inserted record (_8d729efc980cff99911f402d42a02721) in context (MessageFlow) with expiration (1386058644)</div>
<div>2013-12-03 10:46:24 DEBUG OpenSAML.SecurityPolicyRule.BearerConfirmation [2]: assertion satisfied bearer confirmation requirements</div>
<div>2013-12-03 10:46:24 WARN Shibboleth.SSO.SAML2 [2]: detected a problem with assertion: Unable to establish security of incoming assertion.</div>
<div>2013-12-03 10:47:52 DEBUG Shibboleth.Listener [3]: dispatching message (default/SAML2/POST)</div>
<div>2013-12-03 10:47:52 DEBUG OpenSAML.MessageDecoder.SAML2POST [3]: validating input</div>
<div><br>
</div>
<div>I am interested in:</div>
<div>2013-12-03 10:46:24 DEBUG XMLTooling.CredentialCriteria [2]: key algorithm didn't match ('AES' != 'RSA')</div>
<div>but that message is only at DEBUG level</div>
<div><br>
</div>
<div>Do you know where I should look next?</div>
<div><br>
</div>
<div>Thanks!</div>
<div><br>
</div>
<div>Sam</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div>
<div>On Dec 1, 2013, at 3:37 PM, Nate Klingenstein wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
Sam,
<div><br>
</div>
<div>It doesn't require that your IdP server be on the Internet because in normal deployments the IdP and SP never directly communicate with one another. &nbsp;The only requirement is that your client machine(e.g. the web browser) can talk to both the IdP and the
 SP, so if your client already bridges both networks, you should be set to try it out with TestShib.</div>
<div><br>
</div>
<div>Thanks,</div>
<div>Nate.</div>
<div><br>
<div>
<div>On Dec 1, 2013, at 12:59 AM, Sam Agnew &lt;<a href="mailto:saa2012@qatar-med.cornell.edu">saa2012@qatar-med.cornell.edu</a>&gt;</div>
<div>&nbsp;wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">
My team looked with joy at testshib until we realised the server needs to be on the internet to use it. Unfortunately, our security policies and network design don't permit any box we are building to be on DMZ or internet. Therefore we have to fix this some
 other way.</div>
<br class="Apple-interchange-newline">
</blockquote>
</div>
<br>
</div>
</div>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></blockquote>
</div>
<br>
<div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; "><br class="Apple-interchange-newline">
--</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Sam Agnew</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
System Administrator</div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">IT Department</font></div>
<div style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-family: Helvetica; font-size: 12px; ">
<font face="Helvetica" size="3" style="font: normal normal normal 12px/normal Helvetica; ">Weill Cornell Medical College in Qatar</font></div>
<div style="font-family: Helvetica; font-size: 12px; "><br class="webkit-block-placeholder">
</div>
<br class="Apple-interchange-newline">
</div>
<br>
</div>
</body>
</html>