<html><head></head><body><div>Hi Everyone,</div><div><br></div><div>Continuing on with my efforts to get a working IDPv3 configuration, I've been working on a bit of a hurdle with respect to supporting old endpoints.</div><div><br></div><div>What I know is that the existing Shibboleth 2 install, is that it uses Tomcat and is fronted by Apache. Through this setup it rewrites URL's in an effort to maintain legacy URL paths, which to my understanding are SAML1. The mapping is as follows:</div><div><br></div><div>/shibboleth-idp/SSO --> /idp/profile/Shibboleth/SSO</div><div><br></div><div>/shibboleth-idp/AA --> /idp/profile/SAML1/SOAP/AttributeQuery</div><div><br></div><div>Accordingly, I've configured Jetty's rewrite system to accomplish the same. With those in place, I'm able to test existing service providers to the point of logging in, approving attribute release, etc. However at that point, they don't seem to like what they get from the new IDP.</div><div><br></div><div>The most meaningful data I could find stated the error was: Security of SAML 1.x SSO POST response not established, this was from the SP.</div><div><br></div><div>I have Shibboleth running with debug logging on, and quite a bit seems to happen up to the point of failure, though I'm not sure what I should be looking for to troubleshoot.</div><div><br></div><div>For reference, I believe our metadata currently stipulates SAML1 endpoints are in use. I intend to address this as soon as I can but I wanted to get IDPv3 up first. I can include that if desired.</div><div><br></div><div>Thanks for any guidance that can be given on this.</div><div><br></div><div>Regards,</div><div><br></div><div><br></div><div class="-x-evo-signature-wrapper"><span><pre>-- 
Brandon McKean
IT / Systems
Linux Administrator
(540)568-4235</pre></span></div></body></html>