<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">I’m integrating my IdP with a vendor’s Shibboleth SP. I’m puzzled by the error he reports is triggered after receiving my IdP’s SAML:<div><br></div><div><blockquote type="cite"><table cellspacing="0" cellpadding="0" width="100%" style="position: static; z-index: auto;"><tbody><tr><td style="text-align: center; padding-left: 4px;"><table width="100%" style="position: static; z-index: auto;"><tbody><tr><td style="font-size: 12px; font-family: Arial; padding: 8px;"><p style="color: rgb(43, 46, 47); font-size: 14px; line-height: 22px; margin: 15px 0px; font-family: 'Lucida Sans Unicode', 'Lucida Grande', Tahoma, Verdana, sans-serif;">I am seeing the following error when redirected:</p><pre style="font-size: 13px; background-color: rgb(248, 248, 248); border: 1px solid rgb(204, 204, 204); line-height: 19px; padding: 6px 10px; border-top-left-radius: 3px; border-top-right-radius: 3px; border-bottom-right-radius: 3px; border-bottom-left-radius: 3px; margin-top: 15px; margin-bottom: 15px; max-width: 100%; position: static; z-index: auto;"><code style="white-space: pre-wrap; font-family: Consolas, Menlo, Monaco, 'Lucida Console', 'Liberation Mono', 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Courier New', monospace, serif; max-width: 100%; display: block; background-image: none; margin: 0px; padding: 0px; border: 0px none transparent;">Error Message: SAML 2 SSO profile is not configured for relying party <a href="https://uaacommons2.wpengine.com/">https://uaacommons2.wpengine.com</a>
</code></pre><p style="color: rgb(43, 46, 47); font-size: 14px; line-height: 22px; margin: 15px 0px; font-family: 'Lucida Sans Unicode', 'Lucida Grande', Tahoma, Verdana, sans-serif;">The entity ID we are using in apache is <code style="margin: 0px 2px; padding: 0px 5px; white-space: nowrap; border: 1px solid rgb(234, 234, 234); background-color: rgb(248, 248, 248); font-family: Consolas, Menlo, Monaco, 'Lucida Console', 'Liberation Mono', 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Courier New', monospace, serif; font-size: 13px;">urn:mace:uncommon:alaska.edu</code>. Is this correct for your test? Please advise. Thank you.</p></td></tr></tbody></table></td></tr></tbody></table></blockquote><div><br></div></div><div>1) The entity in the Error Message is the vendor’s entityID as per the metadata provided me.</div><div>What would trigger the SP to request relying party configuration for itself?</div><div><br></div><div>2) the entityID of my IdP is urn:mace:incommon:alaska.edu but apart from the amusing typo,</div><div>why would Apache on the service side need my IdP’s entityID?</div><div><br></div><div>3) The first attempt of the vendor to provide their SP metadata at <a href="http://vendor-server/Shibboleth.sso/Metadata" target="_blank" style="margin: 0px; padding: 0px; border: 0px; vertical-align: baseline; text-decoration: none; color: rgb(102, 17, 204); cursor: pointer; font-family: Arial, Helvetica, sans-serif; font-size: 13px; background-color: rgb(255, 255, 255);">http://vendor-server/Shibboleth.<wbr>sso/Metadata</a></div><div>mysteriously had the entityID of my IdP. That particular problem has been corrected by the vendor at my insistence, </div><div>but I wonder if there could be some systematic confusion of IdP and SP on their part.</div><div><br></div><div>David Bantz</div><div>UAlaska</div></body></html>