<div dir="ltr"><div><div><div><div>Thank you Randy, that makes a lot of sense!<br><br>Nevertheless, after enabling FBA and disabling Windows Authentication in the IdP IIS (and the SP IIS) I've broken the SSO and don't get the IdP login form anymore, but instead this error message:<br>
<br><p class="" style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
opensaml::FatalProfileException at (<a href="https://mySP/Shibboleth.sso/SAML2/POST">https://mySP/Shibboleth.sso/SAML2/POST</a>)</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
SAML response reported an IdP error.</p><p style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
Error from identity provider:</p><blockquote style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
<strong>Status:</strong><span class=""> </span>urn:oasis:names:tc:SAML:2.0:status:Responder</blockquote>I've tried to troubleshoot it but nothing really alarming seems to popup from the logs.<br><br></div>The app proxy shows a 500 Server error on the following request:<br>
<br></div>POST <a href="https://mySP/Shibboleth.sso/SAML2/POST">https://mySP/Shibboleth.sso/SAML2/POST</a><br><br></div>Thank you once again<br><br></div>Bida<br></div><div class="gmail_extra"><br><br><div class="gmail_quote">
On Wed, Aug 13, 2014 at 7:17 PM, Randy Wiemer <span dir="ltr"><<a href="mailto:wiemerr@hotmail.com" target="_blank">wiemerr@hotmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">
<div dir="ltr" style="font-family:'Calibri','Segoe UI','Meiryo','Microsoft YaHei UI','Microsoft JhengHei UI','Malgun Gothic','sans-serif';font-size:12pt"><div>You need to configure ADFS to use forms-based authentication in order to achieve SLO. Windows integrated will use Kerberos or NTLM with IE where there is no real concept of logoff short of logging off the computer. With both of those protocols the goal is to use the desktop credentials to seamlessly access web sites.</div>
<div><br></div><div>Randy</div><div><br></div><div><br></div><div style="padding-top:5px;border-top-color:rgb(229,229,229);border-top-width:1px;border-top-style:solid"><div><font style="line-height:15pt;letter-spacing:0.02em;font-family:"Calibri","Segoe UI","Meiryo","Microsoft YaHei UI","Microsoft JhengHei UI","Malgun Gothic","sans-serif";font-size:12pt" face=" 'Calibri', 'Segoe UI', 'Meiryo', 'Microsoft YaHei UI', 'Microsoft JhengHei UI', 'Malgun Gothic', 'sans-serif'"><b>From:</b> <a href="mailto:bidabahia@gmail.com" target="_blank">B Da Bahia</a><br>
<b>Sent:</b> Wednesday, August 13, 2014 11:49 AM<br><b>To:</b> <a href="mailto:users@shibboleth.net" target="_blank">Shib Users</a></font></div></div><div class=""><div><br></div><div dir=""><div dir="ltr"><div>
<div><div><div><div><div><div><div><div><div>Hello list,<br><br></div>Newbie here. I'm attempting to setup a simple SAML 2.0 federation with:<br></div></div></div></div></div></div></div></div></div><div><div><div><div>
<br></div></div></div></div></div>
</div></div></div>
</div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>