<div dir="ltr">Sounds related to the problem I posted about an hour ago - I traced to back to errors when the metadata is submitted. <div><br></div><div>Paul</div></div><div class="gmail_extra"><br><div class="gmail_quote">On 2 July 2015 at 09:51, McNeill, Stu <span dir="ltr"><<a href="mailto:Stu.McNeill@landesk.com" target="_blank">Stu.McNeill@landesk.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-GB" link="#0563C1" vlink="#954F72">
<div>
<p class="MsoNormal">Hi everyone,<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">I’m just trying to test Shibboleth for the first time and using the very useful <a href="http://testshib.org" target="_blank">testshib.org</a> to try hosting the SP and connecting to the Testshib IdP. I can register OK and see my entity ID appear on
<a href="http://testshib.org/entities.html" target="_blank">http://testshib.org/entities.html</a> but when I try to access my “/secure” page I get an error page with message “SAML 2 SSO profile is not configured for relying party (my entity ID) “ and looking at the error log
I see these details:<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">04:34:28.001 - INFO [Shibboleth-Access:73] - 20150702T083428Z|194.168.134.23|idp.testshib.org:443|/profile/SAML2/Redirect/SSO|<u></u><u></u></p>
<p class="MsoNormal">04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:86] - shibboleth.HandlerManager: Looking up profile handler for request path: /SAML2/Redirect/SSO<u></u><u></u></p>
<p class="MsoNormal">04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.IdPProfileHandlerManager:97] - shibboleth.HandlerManager: Located profile handler of the following type for the request path: edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler<u></u><u></u></p>
<p class="MsoNormal">04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.util.HttpServletHelper:339] - LoginContext key cookie was not present in request<u></u><u></u></p>
<p class="MsoNormal">04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:188] - Incoming request does not contain a login context, processing as first leg of request<u></u><u></u></p>
<p class="MsoNormal">04:34:28.002 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:366] - Decoding message with decoder binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect'<u></u><u></u></p>
<p class="MsoNormal">04:34:28.007 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:128] - Looking up relying party configuration for (my entity ID)<u></u><u></u></p>
<p class="MsoNormal">04:34:28.007 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:134] - No custom relying party configuration found for (my entity ID), looking up configuration based on metadata
groups.<u></u><u></u></p>
<p class="MsoNormal">04:34:28.007 - DEBUG [edu.internet2.middleware.shibboleth.common.relyingparty.provider.SAMLMDRelyingPartyConfigurationManager:157] - No custom or group-based relying party configuration found for (my entity ID). Using default relying party
configuration.<u></u><u></u></p>
<p class="MsoNormal"><b>04:34:28.008 - WARN [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:81] - SPSSODescriptor role metadata for entityID '(my entity ID) ' could not be resolved<u></u><u></u></b></p>
<p class="MsoNormal">04:34:28.008 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:387] - Decoded request from relying party '(my entity ID) '<u></u><u></u></p>
<p class="MsoNormal">04:34:28.008 - WARN [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:305] - No metadata for relying party (my entity ID), treating party as anonymous<u></u><u></u></p>
<p class="MsoNormal">04:34:28.008 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:222] - SAML 2 SSO profile is not configured for relying party (my entity ID)<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">I’m seeing other people getting the same error and on searching online I found a post to this mailing list from 6 months ago:
<a href="http://shibboleth.1660669.n2.nabble.com/SPSSODescriptor-role-metadata-for-entityID-could-not-be-resolved-td7610660.html" target="_blank">
http://shibboleth.1660669.n2.nabble.com/SPSSODescriptor-role-metadata-for-entityID-could-not-be-resolved-td7610660.html</a><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">This seemed to suggest to me there is a problem with the IdP, at least for newly registered SPs. Any advice to confirm this? I am asking here because I saw an admin for the site replied and fixed it on their end, could they perform their
same magic again? I couldn’t find any other way to contact the admins.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Thanks<span class="HOEnZb"><font color="#888888"><u></u><u></u></font></span></p><span class="HOEnZb"><font color="#888888">
<p class="MsoNormal">Stu<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
</font></span></div>
</div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>