<div dir="ltr"><div><div><div><div><div>Hi Peter,<br><br></div>Thanks for the response, sorry for the delay on my part. <br><br></div>We are trying to implement/deploy the SAML ECP Profile. We are using a different library for the SP part of it, and require a SOAP endpoint for the SP to talk to the IdP in the context of ECP.<br><br></div>Thanks,<br></div>Regards,<br></div>Akshay<br><div><div><div><div><div><div><div class="gmail_extra"><br><br><div class="gmail_quote">On Mon, Dec 21, 2015 at 10:30 PM, <span dir="ltr"><<a href="mailto:users-request@shibboleth.net" target="_blank">users-request@shibboleth.net</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Send users mailing list submissions to<br>
<a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
<br>
To subscribe or unsubscribe via the World Wide Web, visit<br>
<a href="http://shibboleth.net/mailman/listinfo/users" rel="noreferrer" target="_blank">http://shibboleth.net/mailman/listinfo/users</a><br>
or, via email, send a message with subject or body 'help' to<br>
<a href="mailto:users-request@shibboleth.net">users-request@shibboleth.net</a><br>
<br>
You can reach the person managing the list at<br>
<a href="mailto:users-owner@shibboleth.net">users-owner@shibboleth.net</a><br>
<br>
When replying, please edit your Subject line so it is more specific<br>
than "Re: Contents of users digest..."<br>
<br>
<br>
Today's Topics:<br>
<br>
1. RE: SSO comparison request from executive management (IAM<br>
David Bantz) (Cantor, Scott)<br>
2. How to configure SingleSignOnService using SOAP end-point on<br>
the IdP version 3.2.x (Akshay Kini)<br>
3. Re: How to configure SingleSignOnService using SOAP end-point<br>
on the IdP version 3.2.x (Peter Schober)<br>
<br>
<br>
----------------------------------------------------------------------<br>
<br>
Message: 1<br>
Date: Sun, 20 Dec 2015 19:28:25 +0000<br>
From: "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>><br>
To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
Subject: RE: SSO comparison request from executive management (IAM<br>
David Bantz)<br>
Message-ID:<br>
<<a href="mailto:9846A6064BD102419D06814DD0D78DE1127D8C6A@CIO-TNC-D2MBX02.osuad.osu.edu">9846A6064BD102419D06814DD0D78DE1127D8C6A@CIO-TNC-D2MBX02.osuad.osu.edu</a>><br>
<br>
Content-Type: text/plain; charset="us-ascii"<br>
<br>
> If your managment wants to shell out 1/4 million for enterprise<br>
> software, perhaps they should re-direct those funds to the Shibboleth<br>
> Foundation--I think they'll see a better return.<br>
<br>
Or any open source project for that matter.<br>
<br>
I appreciate the well-argued statement, as I think it's a lot more persuasive coming from somebody not directly affiliated with the software being argued about.<br>
<br>
-- Scott<br>
<br>
<br>
<br>
------------------------------<br>
<br>
Message: 2<br>
Date: Mon, 21 Dec 2015 12:05:00 +0530<br>
From: Akshay Kini <<a href="mailto:kga.official@gmail.com">kga.official@gmail.com</a>><br>
To: <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
Subject: How to configure SingleSignOnService using SOAP end-point on<br>
the IdP version 3.2.x<br>
Message-ID:<br>
<CAFtx=TkhkxJG=<a href="mailto:TWnOBx7FUVLOLyyeneX6naC-rLJrZqjhC3SeQ@mail.gmail.com">TWnOBx7FUVLOLyyeneX6naC-rLJrZqjhC3SeQ@mail.gmail.com</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
Hi,<br>
<br>
New to Shibboleth here.<br>
<br>
Our project uses a SAML SP for SSO, it also requires SAML SOAP Endpoint<br>
based SingleSignOnService, I have implemented the last part.<br>
<br>
I was working on certifying it on Shibboleth, how do I configure SAML SOAP<br>
Endpoint for SingleSignOnService?<br>
<br>
I tried to point it to the ECP end-point "/idp/profile/SAML2/SOAP/ECP", but<br>
I get the following error in the logs:<br>
<br>
<br>
Log Snippet:<br>
2015-12-20 23:32:33,190 - DEBUG<br>
[net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] -<br>
Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of<br>
type<br>
'org.opensaml.saml.saml2.binding.security.impl.ExtractChannelBindingsExtensionsHandler'<br>
on INBOUND message context<br>
2015-12-20 23:32:33,190 - DEBUG<br>
[net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] -<br>
Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on<br>
message context containing a message of type<br>
'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'<br>
2015-12-20 23:32:33,190 - DEBUG<br>
[org.opensaml.saml.saml2.binding.security.impl.ExtractChannelBindingsExtensionsHandler:79]<br>
- Message Handler: Message did not contain any ChannelBindings extensions<br>
2015-12-20 23:32:33,190 - DEBUG<br>
[net.shibboleth.idp.profile.interceptor.impl.WriteProfileInterceptorResultToStorage:68]<br>
- Profile Action WriteProfileInterceptorResultToStorage: No results<br>
available from interceptor context, nothing to store<br>
2015-12-20 23:32:33,190 - DEBUG<br>
[net.shibboleth.idp.profile.interceptor.impl.FilterFlowsByNonBrowserSupport:70]<br>
- Profile Action FilterFlowsByNonBrowserSupport: Retaining flow<br>
'intercept/security-policy/saml2-ecp', it supports non-browser<br>
authentication<br>
2015-12-20 23:32:33,190 - DEBUG<br>
[net.shibboleth.idp.profile.interceptor.impl.FilterFlowsByNonBrowserSupport:82]<br>
- Profile Action FilterFlowsByNonBrowserSupport: Available interceptor<br>
flows after filtering:<br>
'{intercept/security-policy/saml2-ecp=ProfileInterceptorFlowDescriptor{flowId=intercept/security-policy/saml2-ecp,<br>
nonBrowserSupported=true}}'<br>
2015-12-20 23:32:33,190 - DEBUG<br>
[net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:65]<br>
- Profile Action SelectProfileInterceptorFlow: Moving completed flow<br>
intercept/security-policy/saml2-ecp to completed set, selecting next one<br>
2015-12-20 23:32:33,190 - DEBUG<br>
[net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:80]<br>
- Profile Action SelectProfileInterceptorFlow: No flows available to choose<br>
from<br>
2015-12-20 23:32:33,206 - DEBUG<br>
[net.shibboleth.idp.saml.profile.impl.InitializeOutboundMessageContext:149]<br>
- Profile Action InitializeOutboundMessageContext: Initialized outbound<br>
message context<br>
2015-12-20 23:32:33,221 - DEBUG<br>
[net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:369]<br>
- Profile Action PopulateBindingAndEndpointContexts: Attempting to resolve<br>
endpoint of type<br>
{urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService for outbound<br>
message<br>
2015-12-20 23:32:33,221 - TRACE<br>
[net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:384]<br>
- Profile Action PopulateBindingAndEndpointContexts: Candidate outbound<br>
bindings: [urn:oasis:names:tc:SAML:2.0:bindings:PAOS,<br>
urn:ietf:params:xml:ns:samlec]<br>
2015-12-20 23:32:33,221 - DEBUG<br>
[net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:507]<br>
- Profile Action PopulateBindingAndEndpointContexts: Populating template<br>
endpoint for resolution from SAML AuthnRequest<br>
2015-12-20 23:32:33,221 - DEBUG<br>
[org.opensaml.saml.common.binding.AbstractEndpointResolver:220] - Endpoint<br>
Resolver org.opensaml.saml.common.binding.impl.DefaultEndpointResolver:<br>
Returning 2 candidate endpoints of type<br>
{urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService<br>
2015-12-20 23:32:33,221 - DEBUG<br>
[org.opensaml.saml.common.binding.impl.DefaultEndpointResolver:86] -<br>
Endpoint Resolver<br>
org.opensaml.saml.common.binding.impl.DefaultEndpointResolver: Candidate<br>
endpoint binding 'urn:oasis:names:tc:SAML:2.0:bindings:SOAP' not permitted<br>
by input criteria<br>
2015-12-20 23:32:33,221 - DEBUG<br>
[org.opensaml.saml.common.binding.impl.DefaultEndpointResolver:86] -<br>
Endpoint Resolver<br>
org.opensaml.saml.common.binding.impl.DefaultEndpointResolver: Candidate<br>
endpoint binding 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST' not<br>
permitted by input criteria<br>
2015-12-20 23:32:33,221 - DEBUG<br>
[org.opensaml.saml.common.binding.AbstractEndpointResolver:130] - Endpoint<br>
Resolver org.opensaml.saml.common.binding.impl.DefaultEndpointResolver: No<br>
candidate endpoints met criteria<br>
2015-12-20 23:32:33,221 - WARN<br>
[net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:404]<br>
- Profile Action PopulateBindingAndEndpointContexts: Unable to resolve<br>
outbound message endpoint<br>
2015-12-20 23:32:33,237 - WARN<br>
[org.opensaml.profile.action.impl.LogEvent:76] - An error event occurred<br>
while processing the request: EndpointResolutionFailed<br>
2015-12-20 23:32:33,237 - DEBUG<br>
[org.opensaml.saml.common.profile.logic.DefaultLocalErrorPredicate:154] -<br>
No SAMLBindingContext or binding URI available, error must be handled<br>
locally<br>
2015-12-20 23:32:33,253 - DEBUG<br>
[net.shibboleth.idp.saml.profile.impl.InitializeOutboundMessageContextForError:140]<br>
- Profile Action InitializeOutboundMessageContextForError: Outbound message<br>
context already exists, nothing to do<br>
2015-12-20 23:32:33,300 - WARN<br>
[net.shibboleth.idp.saml.profile.impl.SpringAwareMessageEncoderFactory:96]<br>
- Binding URI was not available, unable to lookup message encoder<br>
2015-12-20 23:32:33,300 - ERROR<br>
[org.opensaml.profile.action.impl.EncodeMessage:122] - Profile Action<br>
EncodeMessage: Unable to locate an outbound message encoder<br>
<br>
Thanks,<br>
Regards,<br>
Akshay<br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20151221/e47b1f79/attachment-0001.html" rel="noreferrer" target="_blank">http://shibboleth.net/pipermail/users/attachments/20151221/e47b1f79/attachment-0001.html</a>><br>
<br>
------------------------------<br>
<br>
Message: 3<br>
Date: Mon, 21 Dec 2015 14:46:50 +0100<br>
From: Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>><br>
To: <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
Subject: Re: How to configure SingleSignOnService using SOAP end-point<br>
on the IdP version 3.2.x<br>
Message-ID: <<a href="mailto:20151221134650.GB14736@aco.net">20151221134650.GB14736@aco.net</a>><br>
Content-Type: text/plain; charset=us-ascii<br>
<br>
* Akshay Kini <<a href="mailto:kga.official@gmail.com">kga.official@gmail.com</a>> [2015-12-21 07:35]:<br>
> Our project uses a SAML SP for SSO, it also requires SAML SOAP Endpoint<br>
> based SingleSignOnService, I have implemented the last part.<br>
><br>
> I was working on certifying it on Shibboleth, how do I configure SAML SOAP<br>
> Endpoint for SingleSignOnService?<br>
<br>
What SAML Profile are you trying to implement/deploy?<br>
<a href="https://www.oasis-open.org/committees/download.php/56782/sstc-saml-profiles-errata-2.0-wd-07.pdf" rel="noreferrer" target="_blank">https://www.oasis-open.org/committees/download.php/56782/sstc-saml-profiles-errata-2.0-wd-07.pdf</a><br>
Web Browser SSO? ECP?<br>
-peter<br>
<br>
<br>
------------------------------<br>
<br>
Subject: Digest Footer<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
------------------------------<br>
<br>
End of users Digest, Vol 54, Issue 85<br>
*************************************<br>
</blockquote></div><br></div></div></div></div></div></div></div></div>