<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Wayne,<br>
    <br>
    We obviously have no idea who owns which providers, but in this
    instance, I'm pretty sure it's not you.  I would normally just fix
    it in the short term, but the metadata file has a lot of seriously
    creative things in it so I've moved it to the quarantine pile.<br>
    <br>
    If your metadata appears to have suddenly disappeared and it had
    "cd5948dd7" in a hostname, please recheck it and upload something
    new.<br>
    <br>
    In the intermediate term, the developers probably need to
    double-check the metadata file to ensure any bugs here aren't
    fatal(it's seriously creative) and we need to bug the maintainers of
    TestShib to get it up to v3 again.  I'll provide a copy of the file
    for the developers, but I don't expect this to be a top priority
    because it's an older version.<br>
    <br>
    Long story short, please try again, and thank you for alerting us.<br>
    Nate.<br>
    <br>
    <div class="moz-cite-prefix">On 12/26/2015 09:58 AM, Wayne Woodfield
      wrote:<br>
    </div>
    <blockquote
      cite="mid:08B84762-EFC5-4AD8-ACD1-A02443133BCE@woodfieldfamily.org"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      I’d appreciate any ideas that the community has about this.  I’m
      uploading SP metadata to shibtest, and I get the success message:
      "Your metadata was uploaded successfully” and my metadata file
      gets echoed back to me.   But when I send my SAMLRequest to the
      idp, it doesn’t recognize my entity id, so the metadata didn’t
      seem to take.  When I look at the testshib logs after uploading my
      metadata file, it says:
      <div class=""><br class="">
      </div>
      <div class="">
        <pre class="">11:13:59.447 - ERROR [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:307] - Unable to unmarshall metadata
org.opensaml.xml.io.UnmarshallingException: java.lang.IllegalArgumentException: Invalid format: "2016-12-31T00:00:00Z " is malformed at " "
        at org.opensaml.saml2.metadata.provider.AbstractMetadataProvider.unmarshallMetadata(AbstractMetadataProvider.java:473) ~[opensaml-2.6.0.jar:na]
        at org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider.unmarshallMetadata(AbstractReloadingMetadataProvider.java:304) [opensaml-2.6.0.jar:na]
        at org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider.processNewMetadata(AbstractReloadingMetadataProvider.java:345) [opensaml-2.6.0.jar:na]
        at org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider.refresh(AbstractReloadingMetadataProvider.java:261) [opensaml-2.6.0.jar:na]
        at org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider$RefreshMetadataTask.run(AbstractReloadingMetadataProvider.java:508) [opensaml-2.6.0.jar:na]
        at java.util.TimerThread.mainLoop(Timer.java:555) [na:1.7.0_55]
        at java.util.TimerThread.run(Timer.java:505) [na:1.7.0_55]
Caused by: java.lang.IllegalArgumentException: Invalid format: "2016-12-31T00:00:00Z " is malformed at " "
        at org.joda.time.format.DateTimeFormatter.parseMillis(DateTimeFormatter.java:752) ~[joda-time-2.2.jar:2.2]
        at org.joda.time.convert.StringConverter.getInstantMillis(StringConverter.java:65) ~[joda-time-2.2.jar:2.2]
        at org.joda.time.base.BaseDateTime.<init>(BaseDateTime.java:171) ~[joda-time-2.2.jar:2.2]
        at org.joda.time.DateTime.<init>(DateTime.java:286) ~[joda-time-2.2.jar:2.2]
        at org.opensaml.saml2.metadata.impl.EntityDescriptorUnmarshaller.processAttribute(EntityDescriptorUnmarshaller.java:81) ~[opensaml-2.6.0.jar:na]
        at org.opensaml.xml.io.AbstractXMLObjectUnmarshaller.unmarshallAttribute(AbstractXMLObjectUnmarshaller.java:254) ~[xmltooling-1.4.0.jar:na]
        at org.opensaml.xml.io.AbstractXMLObjectUnmarshaller.unmarshall(AbstractXMLObjectUnmarshaller.java:113) ~[xmltooling-1.4.0.jar:na]
        at org.opensaml.xml.io.AbstractXMLObjectUnmarshaller.unmarshallChildElement(AbstractXMLObjectUnmarshaller.java:355) ~[xmltooling-1.4.0.jar:na]
        at org.opensaml.xml.io.AbstractXMLObjectUnmarshaller.unmarshall(AbstractXMLObjectUnmarshaller.java:127) ~[xmltooling-1.4.0.jar:na]
        at org.opensaml.saml2.metadata.provider.AbstractMetadataProvider.unmarshallMetadata(AbstractMetadataProvider.java:470) ~[opensaml-2.6.0.jar:na]
        ... 6 common frames omitted

</pre>
        <div class="">But this is my metadata file - clearly it doesn’t
          have a malformed date like that:</div>
        <div class=""><span class="code"><br class="">
          </span></div>
        <div class=""><span class="code"><md:EntityDescriptor
            xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
            validUntil="2016-12-26T16:36:20Z"
            cacheDuration="PT1451579780S" entityID="sZ2k4nJiHS"><br
              class="">
              <md:SPSSODescriptor AuthnRequestsSigned="false"
            WantAssertionsSigned="true"
            protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><br
              class="">
                <md:KeyDescriptor use="encryption"><br class="">
                  <ds:KeyInfo xmlns:ds="<a moz-do-not-send="true"
              href="http://www.w3.org/2000/09/xmldsig#" class=""
              target="_top" rel="nofollow" link="external">http://www.w3.org/2000/09/xmldsig#</a>"><br
              class="">
                    <ds:X509Data><br class="">
          <ds:X509Certificate>MIIDUTCCAjigAwIBAgIBADANBgkqhkiG9w0BAQ0FADBCMQswCQYDVQQGEwJ1czEN<br
              class="">
MAsGA1UECAwEVXRhaDEPMA0GA1UECgwGTGFueW9uMRMwEQYDVQQDDApsYW55b24u<br
              class="">
Y29tMB4XDTE1MTIyNDE1MjYwNloXDTI1MTIyMTE1MjYwNlowQjELMAkGA1UEBhMC<br
              class="">
dXMxDTALBgNVBAgMBFV0YWgxDzANBgNVBAoMBkxhbnlvbjETMBEGA1UEAwwKbGFu<br
              class="">
eW9uLmNvbTCCASMwDQYJKoZIhvcNAQEBBQADggEQADCCAQsCggECAM8NGU7O80PP<br
              class="">
HxLZAS6Gvvq6VTJpF5x4Ct5tBwszgqa1gfe4Zpk6G5roGCLC4YOb1qq+ONTJq1xB<br
              class="">
3BkQ5LiGYJY7Ev/JqDwhUdJZVLlnmu7Evn4rVqsp+tH8X46V5ukblCGxQiEjKyYF<br
              class="">
uOEwqGpWfmIfSY96xyqqxI32LfoO8ZTYsXk5W8kalV24HNpK2vmWy4q6UPq35UNs<br
              class="">
qEPb7N6mzKiu5bPjAZDESs3kqhBcJhnUKu3JOR9eMV9r0PRLX59ZOEMh6zBT2hQ0<br
              class="">
+mbGPlfkyX4aspuoDHPOJcW84BTTYi57eY6ePJ8LsZECjoClEYg8jgOt2yJJidQz<br
              class="">
GMRyviW53NcPAgMBAAGjUDBOMB0GA1UdDgQWBBRtKZfJCh+YPoVBxtMGXcTa0IOx<br
              class="">
DDAfBgNVHSMEGDAWgBRtKZfJCh+YPoVBxtMGXcTa0IOxDDAMBgNVHRMEBTADAQH/<br
              class="">
MA0GCSqGSIb3DQEBDQUAA4IBAgBPEGXt8SjDxIM0rWTg3KlvEQvfA609m45z/7fv<br
              class="">
+CdfnUz8m1j+jeLCS1YvLYjcuGd7oCxjDlRoepwtYitWURIFQIgzNXNBjF1GC0wT<br
              class="">
XEUwj9/bS3Nf8I4IKP/Hm1ELrL+4kp0ciHz4B85bQD43EPJdFQR8609uBdQDi2RL<br
              class="">
9LQVbC2yyp6j9HovE7p+hqGbkML7s4YPxZcFrqmqNgM8GTXzWUTWgIRK7my/Hwwm<br
              class="">
MfQ51InVcJdUwseFeMvWLYcApxQ05YOFtu+nVtw1i/aKZRUH1BATScwGHE212AOo<br
              class="">
JKVmi1pZIwOXo9rtcHAdM6BC6pOEsyodouWDFUE24iJZghtTBQ==</ds:X509Certificate><br
              class="">
                    </ds:X509Data><br class="">
                  </ds:KeyInfo><br class="">
                  <md:EncryptionMethod Algorithm="<a
              moz-do-not-send="true"
              href="http://www.w3.org/2001/04/xmlenc#aes128-cbc"
              class="" target="_top" rel="nofollow" link="external"><a class="moz-txt-link-freetext" href="http://www.w3.org/2001/04/xmlenc#aes128-cbc">http://www.w3.org/2001/04/xmlenc#aes128-cbc</a></a>"/><br
              class="">
                </md:KeyDescriptor><br class="">
    <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat><br
              class="">
                <md:AssertionConsumerService
            Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
            Location="<a moz-do-not-send="true"
              href="https://mobile-uat.lanyonevents.com/portal/samlSso.ww"
              class="" target="_top" rel="nofollow" link="external">https://mobile-uat.lanyonevents.com/portal/samlSso.ww</a>"
            index="1"/><br class="">
              </md:SPSSODescriptor><br class="">
            </md:EntityDescriptor></span></div>
        <div class=""><span class="code"><br class="">
          </span></div>
        <div class=""><span class="code">I copy-pasted that metadata
            right out of the testshib upload response, not from my local
            file, so I know this is exactly what testshib is receiving.
             Just to make sure that I wasn’t missing anything, I wrote a
            little code snippet to parse my own metadata file with the
            opensaml unmarshaller, and it unmarshalled it without any
            errors.  I checked my cert, just in case it had any issues,
            and it came out valid.  It’s almost like I’m continually
            getting my file crossed with some other file.  Any thoughts?</span></div>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
    </blockquote>
    <br>
  </body>
</html>