<div dir="ltr">I have been beating my head trying to register my SP with the testshib IdP for the past could of days. I have overhauled my shibboleth2.xml config multiple times and uploaded my metadata, but ever time to try to access my secured directory I get the following error:<div><br></div><div><strong style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium">SAML 2 SSO profile is not configured for relying party <a href="https://shib.zurigroup.com/shibboleth">https://shib.zurigroup.com/shibboleth</a></strong></div><div><font color="#000000" face="Times New Roman" size="3"><b><br></b></font></div><div>I looked into the IdP logs and get the following details:</div><div><span style="color:rgb(0,0,0);font-family:'Times New Roman';font-size:medium"><font color="#222222" face="arial, sans-serif"><br></font></span></div><div><pre style="color:rgb(0,0,0);word-wrap:break-word;white-space:pre-wrap">11:00:15.532 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128] - Looking up relying party configuration for <a href="https://shib.zurigroup.com/shibboleth">https://shib.zurigroup.com/shibboleth</a>
11:00:15.532 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134] - No custom relying party configuration found for <a href="https://shib.zurigroup.com/shibboleth">https://shib.zurigroup.com/shibboleth</a>, looking up configuration based on metadata groups.
11:00:15.533 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157] - No custom or group-based relying party configuration found for <a href="https://shib.zurigroup.com/shibboleth">https://shib.zurigroup.com/shibboleth</a>. Using default relying party configuration.
11:00:15.533 - WARN [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:81] - SPSSODescriptor role metadata for entityID '<a href="https://shib.zurigroup.com/shibboleth">https://shib.zurigroup.com/shibboleth</a>' could not be resolved
11:00:15.534 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:387] - Decoded request from relying party '<a href="https://shib.zurigroup.com/shibboleth">https://shib.zurigroup.com/shibboleth</a>'
11:00:15.534 - WARN [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:305] - No metadata for relying party <a href="https://shib.zurigroup.com/shibboleth">https://shib.zurigroup.com/shibboleth</a>, treating party as anonymous</pre><div>I looked on the TestShib.org About/Current Entity List and ensure that my EntityID is listed and it is:</div><div><br></div><div><font color="#000000"><strong style="font-family:'Open Sans',sans-serif;font-size:15px;background-color:rgb(244,244,244)">EntityID</strong><span style="font-family:'Open Sans',sans-serif;font-size:15px;background-color:rgb(244,244,244)"> <a href="https://shib.zurigroup.com/shibboleth">https://shib.zurigroup.com/shibboleth</a></span><br></font></div><div><span style="font-family:'Open Sans',sans-serif;font-size:15px;background-color:rgb(244,244,244)"><font color="#000000"><br></font></span></div><div><span style="font-family:'Open Sans',sans-serif;font-size:15px;background-color:rgb(244,244,244)"><font color="#000000">Anyone have any ideas?</font></span></div><div><span style="color:rgb(25,25,25);font-family:'Open Sans',sans-serif;font-size:15px;background-color:rgb(244,244,244)"><br></span></div><div><span style="color:rgb(25,25,25);font-family:'Open Sans',sans-serif;font-size:15px;background-color:rgb(244,244,244)"><br></span></div><div><font color="#191919" face="Open Sans, sans-serif"><span style="font-size:15px;background-color:rgb(244,244,244)">For reference here is my metadata:</span></font></div><div><font color="#191919" face="Open Sans, sans-serif"><span style="font-size:15px;background-color:rgb(244,244,244)"><br></span></font></div><div><span style="font-size:15px;background-color:rgb(244,244,244)"><font color="#191919" face="Open Sans, sans-serif"><div style><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_989e564f01aa0e26eba49692bcfb9685a62e71af" entityID="<a href="https://shib.zurigroup.com/shibboleth">https://shib.zurigroup.com/shibboleth</a>"></div><div style><br></div><div style> <md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"></div><div style> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha512">http://www.w3.org/2001/04/xmlenc#sha512</a>"/></div><div style> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#sha384">http://www.w3.org/2001/04/xmldsig-more#sha384</a>"/></div><div style> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>"/></div><div style> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#sha224">http://www.w3.org/2001/04/xmldsig-more#sha224</a>"/></div><div style> <alg:DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512">http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384">http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256">http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224">http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512">http://www.w3.org/2001/04/xmldsig-more#rsa-sha512</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384">http://www.w3.org/2001/04/xmldsig-more#rsa-sha384</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2009/xmldsig11#dsa-sha256">http://www.w3.org/2009/xmldsig11#dsa-sha256</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1">http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>"/></div><div style> <alg:SigningMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#dsa-sha1">http://www.w3.org/2000/09/xmldsig#dsa-sha1</a>"/></div><div style> </md:Extensions></div><div style><br></div><div style> <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"></div><div style> <md:Extensions></div><div style> <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/Login">https://shib.zurigroup.com/Shibboleth.sso/Login</a>"/></div><div style> </md:Extensions></div><div style> <md:KeyDescriptor></div><div style> <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"></div><div style> <ds:KeyName><a href="https://idp.testshib.org/idp/shibboleth">https://idp.testshib.org/idp/shibboleth</a></ds:KeyName></div><div style> <ds:KeyName><a href="http://shib.zurigroup.com">shib.zurigroup.com</a></ds:KeyName></div><div style> <ds:X509Data></div><div style> <ds:X509SubjectName>CN=<a href="http://shib.zurigroup.com">shib.zurigroup.com</a></ds:X509SubjectName></div><div style> <ds:X509Certificate>MIIDJjCCAg6gAwIBAgIJAKf+olmYWxHoMA0GCSqGSIb3DQEBBQUAMB0xGzAZBgNV</div><div style>BAMTEnNoaWIuenVyaWdyb3VwLmNvbTAeFw0xNTAxMDkwNDEzMjJaFw0yNTAxMDYw</div><div style>NDEzMjJaMB0xGzAZBgNVBAMTEnNoaWIuenVyaWdyb3VwLmNvbTCCASIwDQYJKoZI</div><div style>hvcNAQEBBQADggEPADCCAQoCggEBALbRR3ny9hEEV2ut8W4jokvzAnbWL6Z+FCHL</div><div style>yt/rppTwmVzX0HLwLo+oxzRaW2CkYGXNAc6VAPwawXPmm9oAQNrF8Q/ZUpUn1urs</div><div style>jMZbjf4Xdio9CfLq2Nokip/+txMf4RpCucAX6jHrq67QkaJfYFbmjiqYXNq3mZxe</div><div style>jx6J6tS32CZQC4k6+IpgMofCwFecwqjqnwAIM/Y60PdRjuIqwbkHBADEMkXmGkq3</div><div style>uviydm3trNUO9oa8pYpwbZ8ClLYHG5HVRxJs2SL7QX4PRH6KrrEgkI/EG0QvaWyq</div><div style>Me5XVPF7du3WF86/+VMR1VlrSDcPHj1/Ct5YvxcvCFTxT2RJuOMCAwEAAaNpMGcw</div><div style>RgYDVR0RBD8wPYISc2hpYi56dXJpZ3JvdXAuY29thidodHRwczovL2lkcC50ZXN0</div><div style>c2hpYi5vcmcvaWRwL3NoaWJib2xldGgwHQYDVR0OBBYEFEhSSSTn6XlmnITYjLGQ</div><div style>LYjoR9lxMA0GCSqGSIb3DQEBBQUAA4IBAQAmNeU2pC/RatTwr3CicLEa/KB/RSl7</div><div style>Iff88J/+1OwHY3izVv2+8OQmjCy/nP8Bnco8XsNz2O3OqNvXISG0dpKu75lNBHzs</div><div style>vPK0qfoP2FPUwXkrJ24pQRt35FtrHAq/uSf+NMuupZdHq7yWoc5eTCBKekjFMD8I</div><div style>+3dksquQMGsIwFx2vs9Rg/RbAwgxJO0Ay51f3OBohFNVJsohe9Uf6dqXLi2WXvBQ</div><div style>I+C58dRZcN+ZQGNSJSVIGqoFcpW+jjf1jc47scUJPssQoECWWRq9vO0nm/5Ca8LB</div><div style>j1D19y89FUn9SYgL5K/eD7VlJ+jwoT7gTJP/XlxOdw1MhVcoe4OVKM6Z</div><div style></ds:X509Certificate></div><div style> </ds:X509Data></div><div style> </ds:KeyInfo></div><div style> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2009/xmlenc11#aes128-gcm">http://www.w3.org/2009/xmlenc11#aes128-gcm</a>"/></div><div style> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2009/xmlenc11#aes192-gcm">http://www.w3.org/2009/xmlenc11#aes192-gcm</a>"/></div><div style> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2009/xmlenc11#aes256-gcm">http://www.w3.org/2009/xmlenc11#aes256-gcm</a>"/></div><div style> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes128-cbc">http://www.w3.org/2001/04/xmlenc#aes128-cbc</a>"/></div><div style> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes192-cbc">http://www.w3.org/2001/04/xmlenc#aes192-cbc</a>"/></div><div style> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes256-cbc">http://www.w3.org/2001/04/xmlenc#aes256-cbc</a>"/></div><div style> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#tripledes-cbc">http://www.w3.org/2001/04/xmlenc#tripledes-cbc</a>"/></div><div style> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2009/xmlenc11#rsa-oaep">http://www.w3.org/2009/xmlenc11#rsa-oaep</a>"/></div><div style> <md:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p">http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p</a>"/></div><div style> </md:KeyDescriptor></div><div style> <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/Artifact/SOAP">https://shib.zurigroup.com/Shibboleth.sso/Artifact/SOAP</a>" index="1"/></div><div style> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/SLO/SOAP">https://shib.zurigroup.com/Shibboleth.sso/SLO/SOAP</a>"/></div><div style> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/SLO/Redirect">https://shib.zurigroup.com/Shibboleth.sso/SLO/Redirect</a>"/></div><div style> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/SLO/POST">https://shib.zurigroup.com/Shibboleth.sso/SLO/POST</a>"/></div><div style> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/SLO/Artifact">https://shib.zurigroup.com/Shibboleth.sso/SLO/Artifact</a>"/></div><div style> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/SAML2/POST">https://shib.zurigroup.com/Shibboleth.sso/SAML2/POST</a>" index="1"/></div><div style> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/SAML2/POST-SimpleSign">https://shib.zurigroup.com/Shibboleth.sso/SAML2/POST-SimpleSign</a>" index="2"/></div><div style> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/SAML2/Artifact">https://shib.zurigroup.com/Shibboleth.sso/SAML2/Artifact</a>" index="3"/></div><div style> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/SAML2/ECP">https://shib.zurigroup.com/Shibboleth.sso/SAML2/ECP</a>" index="4"/></div><div style> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/SAML/POST">https://shib.zurigroup.com/Shibboleth.sso/SAML/POST</a>" index="5"/></div><div style> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="<a href="https://shib.zurigroup.com/Shibboleth.sso/SAML/Artifact">https://shib.zurigroup.com/Shibboleth.sso/SAML/Artifact</a>" index="6"/></div><div style> </md:SPSSODescriptor></div><div style><br></div><div style></md:EntityDescriptor></div></font></span></div><div>-- <br></div><div class="gmail_signature">Ken Swift<br><a href="mailto:ken@netoutlook.com">ken@netoutlook.com</a></div>
</div></div>