<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;"><div>Hi,&nbsp;</div><div><br></div><div>I am trying to deploy shibboleth IDP and SP on a single virtual server inside a physical machine, whose address is <a href="https://dcotest.tw.rpi.edu">https://dcotest.tw.rpi.edu</a>. I followed the tutorial of installation and everything looks fine except going to <a href="https://dcotest.tw.rpi.edu/secure">https://dcotest.tw.rpi.edu/secure</a>, where it says: Error Message: Message did not meet security requirements. And when I look into the log file of IDP, I found:&nbsp;</div><div><br></div>00:52:38.111 - ERROR [org.opensaml.common.binding.decoding.BaseSAMLMessageDecoder:215] - SAML message intended destination endpoint '<a href="https://dcotest.tw.rpi.edu/idp/profile/SAML2/Redirect/SSO'">https://dcotest.tw.rpi.edu/idp/profile/SAML2/Redirect/SSO'</a> did not match the recipient endpoint '<a href="http://localhost:8080/idp/profile/SAML2/Redirect/SSO'">http://localhost:8080/idp/profile/SAML2/Redirect/SSO'</a><div><br></div><div>I found that there was someone else raising similar problems before, which is&nbsp;<a href="http://shibboleth.1660669.n2.nabble.com/SAML-message-intended-destination-endpoint-td6653987.html#a6654327">http://shibboleth.1660669.n2.nabble.com/SAML-message-intended-destination-endpoint-td6653987.html#a6654327</a>. Someone suggest that to look into the IDP metadata to make sure there is no ‘localhost’ path, which I double checked my file and found none.&nbsp;</div><div><br></div><div>Can anyone help me on this? Is there anywhere else that IDP will somehow use localhost as the prefix? Thanks!</div><div><br></div><div>Cheers</div><div>Yu</div><div><br></div></body></html>