<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="SL" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">Hello,<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">I'm new to Shibboleth and i'm trying to set it up as SSO for couple of applications. I have installed Shibboleth IdP and SP. I have managed to have the login page show up and have the user authenticate against OpenLDAP. But after that i'm
 stuck with error &nbsp;&raquo;No peer endpoint available to which to send SAML response.&laquo;<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">In the idp-process.log i see the following error:<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">14:21:46.411 - INFO [Shibboleth-Access:73] - 20150413T142146Z|10.10.1.2|netshib.ixtlan-dev.si:8443|/profile/Metadata/SAML|<o:p></o:p></p>
<p class="MsoNormal">14:24:33.488 - INFO [Shibboleth-Access:73] - 20150413T142433Z|10.10.1.2|netshib.ixtlan-dev.si:8443|/profile/SAML2/Redirect/SSO|<o:p></o:p></p>
<p class="MsoNormal">14:24:33.489 - DEBUG [PROTOCOL_MESSAGE:113] -<o:p></o:p></p>
<p class="MsoNormal">&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;<o:p></o:p></p>
<p class="MsoNormal">&lt;samlp:AuthnRequest<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; AssertionConsumerServiceURL=&quot;https://netshib.ixtlan-dev.si/Shibboleth.sso/SAML2/POST&quot;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; Destination=&quot;https://netshib.ixtlan-dev.si:8443/idp/profile/SAML2/Redirect/SSO&quot;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; ID=&quot;_5137de30e536fce539345aacbba9ffe0&quot;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; IssueInstant=&quot;2015-04-13T14:24:33Z&quot;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; ProtocolBinding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; Version=&quot;2.0&quot; xmlns:samlp=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot;&gt;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; &lt;saml:Issuer xmlns:saml=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot;&gt;https://netshib.ixtlan-dev.si:8443/idp/shibboleth&lt;/saml:Issuer&gt;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; &lt;samlp:NameIDPolicy AllowCreate=&quot;1&quot;/&gt;<o:p></o:p></p>
<p class="MsoNormal">&lt;/samlp:AuthnRequest&gt;<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">14:24:33.490 - WARN [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:81] - SPSSODescriptor role metadata for entityID 'https://netshib.ixtlan-dev.si:8443/idp/shibboleth' could not be resolved<o:p></o:p></p>
<p class="MsoNormal">14:24:33.490 - INFO [org.opensaml.common.binding.security.SAMLProtocolMessageXMLSignatureSecurityPolicyRule:100] - SAML protocol message was not signed, skipping XML signature processing<o:p></o:p></p>
<p class="MsoNormal">14:24:33.495 - INFO [Shibboleth-Access:73] - 20150413T142433Z|10.10.1.2|netshib.ixtlan-dev.si:8443|/profile/SAML2/Redirect/SSO|<o:p></o:p></p>
<p class="MsoNormal">14:24:33.498 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:447] - No return endpoint available for relying party https://netshib.ixtlan-dev.si:8443/idp/shibboleth<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">From what I have seen on some web sites the problem could be if AssertionConsumerServiceURL in SAML request would not be the same as URL in SP metadata. But the SP metadata has correct AssertionConsumerService URLs:<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">&#8230;.<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Location=&quot;https://netshib.ixtlan-dev.si/Shibboleth.sso/SAML2/POST&quot; index=&quot;1&quot;/&gt;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign&quot; Location=&quot;https://netshib.ixtlan-dev.si/Shibboleth.sso/SAML2/POST-SimpleSign&quot; index=&quot;2&quot;/&gt;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact&quot; Location=&quot;https://netshib.ixtlan-dev.si/Shibboleth.sso/SAML2/Artifact&quot; index=&quot;3&quot;/&gt;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:PAOS&quot; Location=&quot;https://netshib.ixtlan-dev.si/Shibboleth.sso/SAML2/ECP&quot; index=&quot;4&quot;/&gt;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:1.0:profiles:browser-post&quot; Location=&quot;https://netshib.ixtlan-dev.si/Shibboleth.sso/SAML/POST&quot; index=&quot;5&quot;/&gt;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp; &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:1.0:profiles:artifact-01&quot; Location=&quot;https://netshib.ixtlan-dev.si/Shibboleth.sso/SAML/Artifact&quot; index=&quot;6&quot;/&gt;<o:p></o:p></p>
<p class="MsoNormal">&nbsp; &lt;/md:SPSSODescriptor&gt;<o:p></o:p></p>
<p class="MsoNormal">&#8230;.<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">I have checked the troubleshooting page (<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPTroubleshootingCommonErrors">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPTroubleshootingCommonErrors</a> ), but I'm not
 not really sure what else to look for to resolve the error?<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>