<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Verdana;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p
        {mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
        {mso-style-priority:99;
        mso-style-link:"Balloon Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:8.0pt;
        font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
        {mso-style-name:"Balloon Text Char";
        mso-style-priority:99;
        mso-style-link:"Balloon Text";
        font-family:"Tahoma","sans-serif";}
p.error, li.error, div.error
        {mso-style-name:error;
        mso-style-priority:99;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
span.EmailStyle21
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.EmailStyle22
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">I recall that there was a Shib bug in older IdP versions (sorry, can’t find the reference right now) where AudienceRestrictions weren’t properly handled. If you’re not on the most up to date version that could
be the issue.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">--- Eric<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div style="border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt">
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Josh Christensen<br>
<b>Sent:</b> Monday, March 17, 2014 2:44 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Assertion contains an unacceptable AudienceRestriction<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">The error:<o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:"Verdana","sans-serif";color:black">opensaml::FatalProfileException at (<a href="http://test.mysite.com:8080/Shibboleth.sso/SAML2/POST">http://test.mysite.com:8080/Shibboleth.sso/SAML2/POST</a>)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:8.5pt;font-family:"Verdana","sans-serif";color:black">Assertion contains an unacceptable AudienceRestriction.</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">ISAPI section:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><Site id="3" name="test.mysite.com" scheme="http" port="8080" /><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Request Map<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><RequestMap entityID="<a href="http://saml.clientidpserver.com">http://saml.clientidpserver.com</a>" applicationId="SSOTest"><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><Host name="test.mysite.com" scheme="http" port="8080"><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><Path name="test" authType="shibboleth" requireSession="false"/><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><Path name="home/test" authType="shibboleth" requireSession="false"/><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"></Host><o:p></o:p></p>
<p class="MsoNormal"></RequestMap><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">SSO declaration<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><SSO entityId="<a href="http://saml.clientidpserver.com">http://saml.clientidpserver.com</a>" discoveryProtocol="SAMLDS" discoveryURL="<a href="https://www2.accp.clientidpserver.com/esamloutbound/saml?target=Mysite">https://www2.accp.clientidpserver.com/esamloutbound/saml?target=Mysite</a>"><o:p></o:p></p>
<p class="MsoNormal">SAML2<o:p></o:p></p>
<p class="MsoNormal"></SSO><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Application override<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><ApplicationOverride id="SSOTest" entityID="<a href="http://test.ftnirdc.com:8080">http://test.ftnirdc.com:8080</a>" /><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Metadata xml<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><?xml version="1.0" encoding="UTF-8"?><o:p></o:p></p>
<p class="MsoNormal"><EntityDescriptor entityID="<a href="http://saml.clientidpserver.com">http://saml.clientidpserver.com</a>" xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xsi="<a href="https://www.w3.org/2001/XMLSchema-instance">https://www.w3.org/2001/XMLSchema-instance</a>">
<o:p></o:p></p>
<p class="MsoNormal"> <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" WantAuthnRequestsSigned="false">
<o:p></o:p></p>
<p class="MsoNormal"> <KeyDescriptor use="signing">
<o:p></o:p></p>
<p class="MsoNormal"> <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>">
<o:p></o:p></p>
<p class="MsoNormal"> <ds:X509Data>
<o:p></o:p></p>
<p class="MsoNormal"> <ds:X509Certificate><o:p></o:p></p>
<p class="MsoNormal">
<o:p></o:p></p>
<p class="MsoNormal"> </ds:X509Certificate><o:p></o:p></p>
<p class="MsoNormal"> </ds:X509Data>
<o:p></o:p></p>
<p class="MsoNormal"> </ds:KeyInfo>
<o:p></o:p></p>
<p class="MsoNormal"> </KeyDescriptor> <o:p></o:p></p>
<p class="MsoNormal"><!-- Supported Name Identifier Formats --><o:p></o:p></p>
<p class="MsoNormal"> <NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat>
<o:p></o:p></p>
<p class="MsoNormal"><!-- AuthenticationRequest Consumer endpoint --><o:p></o:p></p>
<p class="MsoNormal"> <SingleSignOnService isDefault="true" index="0" Location="<a href="https://www2.accp.clientidpserver.com/esamloutbound/saml?target=Mysite">https://www2.accp.clientidpserver.com/esamloutbound/saml?target=Mysite</a>"
Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"/> <o:p></o:p></p>
<p class="MsoNormal"> </IDPSSODescriptor> <o:p></o:p></p>
<p class="MsoNormal"> </EntityDescriptor><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">All the searches on google point to the entity ID being wrong, but as you can see, it matches. We also had the IDP try changing the audience to several variations, none of which worked. I told the IDP that it should be
<a href="http://test.mysite.com:8080">http://test.mysite.com:8080</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Any ideas what is wrong?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Josh<o:p></o:p></p>
</div>
</div>
</body>
</html>