<div dir="ltr"><div><div><div><div>Hi Paul,<br><br></div>I have installed SAML Trace. I get following trace from the plugin:<br><br><br><pre id="txt"><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
AssertionConsumerServiceURL="<a href="https://idp.rosmini.school.nz/Shibboleth.sso/SAML2/POST">https://idp.rosmini.school.nz/Shibboleth.sso/SAML2/POST</a>"
Destination="<a href="https://idp.rosmini.school.nz/idp/profile/SAML2/Redirect/SSO">https://idp.rosmini.school.nz/idp/profile/SAML2/Redirect/SSO</a>"
ID="_8b677a03966229fa6253887da45d58c2"
IssueInstant="2014-08-13T23:13:31Z"
ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Version="2.0"
>
<saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://idp.rosmini.school.nz/idp/shibboleth">https://idp.rosmini.school.nz/idp/shibboleth</a></saml:Issuer>
<samlp:NameIDPolicy AllowCreate="1" />
</samlp:AuthnRequest></pre><br><br></div>I then matched it with the metadata Provided to IdP.<br><br></div>Following value exists which matches the SP AuthnRequest:<br><br><md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol<br>
<br></div><div>My "entityID" is <br><pre id="txt"><a href="https://idp.rosmini.school.nz/idp/shibboleth">https://idp.rosmini.school.nz/idp/shibboleth</a></pre></div><div><br><br></div><div>There is no mismatch<br>
</div>Any further ideas?<br></div><div class="gmail_extra"><br><br><div class="gmail_quote">On 14 August 2014 10:54, Paul Hethmon <span dir="ltr"><<a href="mailto:paul.hethmon@clareitysecurity.com" target="_blank">paul.hethmon@clareitysecurity.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div style="word-wrap:break-word"><div class="">
On Aug 13, 2014, at 6:48 PM, Farzan Qureshi <<a href="mailto:fqureshi@rosmini.school.nz" target="_blank">fqureshi@rosmini.school.nz</a>> wrote:<br>
<div><br>
<blockquote type="cite">
<div dir="ltr" style="font-family:Helvetica;font-size:14px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">
<strong>Error Message: No peer endpoint available to which to send SAML response</strong><br>
</div>
<br>
</blockquote>
</div>
<div><br>
</div>
</div><div>This means the ACS URL in your AuthnRequest does not match any ACS URL in the metadata given to the IdP. ACS URL's are an EXACT match, case included, etc. Your SP is sending something that is wrong, or you gave the IdP the wrong metadata. Either way, it
doesn't match.</div>
<div><br>
</div>
<div>Get a copy of FireFox and install the SAML Tracer plugin. Open SAML Tracer and run your test. You will see the exact value in the AuthnRequest the SP is sending. Match it against the metadata provided to the IdP. Then trace back to figure out why they
are different.</div>
<div><br>
</div>
<div>Paul</div><span class="HOEnZb"><font color="#888888">
<br>
<div>Paul Hethmon<br>
Chief Software Architect<br>
<a href="mailto:paul.hethmon@clareitysecurity.com" target="_blank">paul.hethmon@clareitysecurity.com</a><br>
<br>
</div>
<br>
</font></span></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><br>-- <br><font face="tahoma, sans-serif"><b>Farzan Qureshi</b> | Network Administrator & Help-desk Support | Rosmini College | (09) 487 0 530</font>
</div>
<br>
<font style="font-family:Verdana" size="1">This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager (<span style="font-weight:bold;font-style:italic"><a href="mailto:admin@rosmini.school.nz" target="_blank">admin@rosmini.school.nz</a></span>). Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the company. Finally, the recipient should check this email and any attachments for the presence of viruses. <span style="font-weight:bold">Rosmini College</span> accepts no liability for any damage caused by any virus transmitted by this email.</font>