<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div>Hi Remi,</div>
<div><br>
</div>
<div>That error can come up if entityids don't match up in metadata. If the file you have configured there is in place, I would take a look at it and make sure the entityID is what it should be.</div>
<div><br>
</div>
<div>Brandon</div>
<div><br>
</div>
<div>On Fri, 2015-07-24 at 10:59 -0400, Remi Mayrand-Provencher wrote:</div>
<blockquote type="cite">I finally got both my service provider and my Identity Provider working with testshib so now it is time to make them work together. According to the documentation, I think the only changes I need to make are in shibboleth2.xml to be
able to make a basic test. I've tried to link my idp to my sp by modifying those next few things in my shibboleth2.xml file, where
<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=">
"https://test-idp-remi/idp/shibboleth"</a> is my idp's entityID.<br>
<br>
<SSO entityID="<b><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=">https://test-idp-remi/idp/shibboleth</a></b>"><br>
SAML2 SAML1<br>
</SSO><br>
<br>
<MetadataProvider type="XML" uri="<b><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=">https://test-idp-remi/idp/shibboleth</a></b>"<br>
backingFilePath="testRemi-tshib-two-idp-metadata.xml" reloadInterval="180000" /><br>
<br>
Still, when I try to reach kohaprod.inlibro.net/Shibboleth.sso/Login, all I get is this :<br>
<p class="error"><br>
opensaml::saml2md::MetadataException at (<a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__kohaprod.inlibro.net_Shibboleth.sso_Login&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=6Ge0cflMBzMLVmzSZvAKG4L6HRFV2i9aVtI09U9jkwI&e=">http://kohaprod.inlibro.net/Shibboleth.sso/Login</a>)</p>
<p>Unable to locate metadata for identity provider (<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=">https://test-idp-remi/idp/shibboleth</a>)<br>
</p>
<p><br>
</p>
<p>Here is my complete shibboleth2.xml file, if it helps. I took the one from testshib since I just want to try to be redirected to my idp.<br>
</p>
<p><br>
</p>
<SPConfig xmlns="urn:mace:shibboleth:2.0:native:sp:config" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"<br>
clockSkew="1800"><br>
<br>
<!-- The entityID is the name TestShib made for your SP. --><br>
<ApplicationDefaults entityID=<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__kohaprod.inlibro.net_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=lrNmcWZ-36bS0rgvX_72KKOayQivcADB-UYNkVeZkyM&e=">"https://kohaprod.inlibro.net/shibboleth"</a><br>
REMOTE_USER="eppn"><br>
<br>
<!-- You should use secure cookies if at all possible. See cookieProps in this Wiki article. --><br>
<!-- <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_SHIB2_NativeSPSessions&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=fyyj4GMWmtv_l-MT8lrS7ApAB-NtPsGgED7ptH6As4w&e=">
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessions</a> --><br>
<Sessions lifetime="28800" timeout="3600" checkAddress="false" relayState="ss:mem" handlerSSL="false"><br>
<br>
<!-- Triggers a login request directly to the TestShib IdP. --><br>
<!-- <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_SHIB2_NativeSPServiceSSO&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=kXUaKziYgJ90IGyq5eYzOcc2q_fM3H7Z2nIyYcns4sI&e=">
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPServiceSSO</a> --><br>
<SSO entityID=<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=">"https://test-idp-remi/idp/shibboleth"</a>><br>
SAML2 SAML1<br>
</SSO><br>
<br>
<!-- SAML and local-only logout. --><br>
<!-- <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_SHIB2_NativeSPServiceLogout&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=4x-fuMpSZGQDVwJtf4_M_KMlgEaN4zNqe76lwtAZSvw&e=">
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPServiceLogout</a> --><br>
<Logout>SAML2 Local</Logout><br>
<br>
<!--<br>
Handlers allow you to interact with the SP and gather more information. Try them out!<br>
Attribute values received by the SP through SAML will be visible at:<br>
<a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__kohaprod.inlibro.net_Shibboleth.sso_Session&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=oV8vyooAZ5LOMxrTNeoC1FfzRxK7AAUMETfIT4Hf5fQ&e=">
http://kohaprod.inlibro.net/Shibboleth.sso/Session</a><br>
--><br>
<br>
<!-- Extension service that generates "approximate" metadata based on SP configuration. --><br>
<Handler type="MetadataGenerator" Location="/Metadata" signing="false"/><br>
<br>
<!-- Status reporting service. --><br>
<Handler type="Status" Location="/Status" acl="127.0.0.1"/><br>
<br>
<!-- Session diagnostic service. --><br>
<Handler type="Session" Location="/Session" showAttributeValues="true"/><br>
<br>
<!-- JSON feed of discovery information. --><br>
<Handler type="DiscoveryFeed" Location="/DiscoFeed"/><br>
<br>
</Sessions><br>
<br>
<!-- Error pages to display to yourself if something goes horribly wrong. --><br>
<Errors supportContact=<a href="mailto:remi.mayrand-provencher@inlibro.com">"remi.mayrand-provencher@inlibro.com"</a> logoLocation="/shibboleth-sp/logo.jpg"<br>
styleSheet="/shibboleth-sp/main.css"/><br>
<br>
<!-- Loads and trusts a metadata file that describes only the Testshib IdP and how to communicate with it. --><br>
<MetadataProvider type="XML" uri=<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__test-2Didp-2Dremi_idp_shibboleth&d=BQMDaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=iZ_ekq9_90q96juMacb0Sg&m=PjeY3ENwIEftdwkErZ1I1DiAbxskALPgKCMZCsz7Nts&s=V_Byq_O6tEafyVfXrk9m8EMtpPgw0c9oXCICvuignSI&e=">"https://test-idp-remi/idp/shibboleth"</a><br>
backingFilePath="testRemi-tshib-two-idp-metadata.xml" reloadInterval="180000" /><br>
<br>
<!-- Attribute and trust options you shouldn't need to change. --><br>
<AttributeExtractor type="XML" validate="true" path="attribute-map.xml"/><br>
<AttributeResolver type="Query" subjectMatch="true"/><br>
<AttributeFilter type="XML" validate="true" path="attribute-policy.xml"/><br>
<br>
<!-- Your SP generated these credentials. They're used to talk to IdP's. --><br>
<CredentialResolver type="File" key="sp-key.pem" certificate="sp-cert.pem"/><br>
<br>
</ApplicationDefaults><br>
<br>
<!-- Security policies you shouldn't change unless you know what you're doing. --><br>
<SecurityPolicyProvider type="XML" validate="true" path="security-policy.xml"/><br>
<br>
<!-- Low-level configuration about protocols and bindings available for use. --><br>
<ProtocolProvider type="XML" validate="true" reloadChanges="false" path="protocols.xml"/><br>
<br>
</SPConfig><br>
<br>
Are there any changes that I am missing if I want to test being redirected to my idp by accessing kohaprod.inlibro.net/Shibboleth.sso/Login?<br>
<pre>--
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></pre>
</blockquote>
</body>
</html>