<div dir="ltr"><div>Hello Scott, <br></div><div>Thanks for the reply<br></div><div>I am trying to send attributes from idp to sp. I configured the soap back channel for this (any other suggestions?)<br></div><div>I get an error because the sp can't identity tomcat certificate!<br></div><div>this is the error i get:<br><div style="font-size:12.8px">2016-01-22 12:41:38 INFO Shibboleth.Listener : listener service starting</div><div style="font-size:12.8px">2016-01-22 12:42:17 ERROR XMLTooling.SOAPTransport.CURL [1]: supplied TrustEngine failed to validate SSL/TLS server certificate</div><div style="font-size:12.8px">2016-01-22 12:42:17 ERROR XMLTooling.SOAPTransport.CURL [1]: Certificate:</div><div style="font-size:12.8px"><br></div><div style="font-size:12.8px">2016-01-22 12:42:17 ERROR Shibboleth.AttributeResolver.Query [1]: exception during SAML query to <a href="https://localhost:8443/idp/profile/SAML2/SOAP/AttributeQuery" target="_blank">https://localhost:8443/idp/profile/SAML2/SOAP/AttributeQuery</a>: CURLSOAPTransport failed while contacting SOAP endpoint (<a href="https://localhost:8443/idp/profile/SAML2/SOAP/AttributeQuery" target="_blank">https://localhost:8443/idp/profile/SAML2/SOAP/AttributeQuery</a>): SSL certificate problem: application verification failure</div><div style="font-size:12.8px">2016-01-22 12:42:17 ERROR Shibboleth.AttributeResolver.Query [1]: unable to obtain a SAML response from attribute authority</div><div style="font-size:12.8px">2016-01-22 12:42:17 INFO Shibboleth.SessionCache [1]: new session created: ID (_04e70c190b8b7c9f5d2097632a420471) IdP (<a href="https://localhost:8443/idp/shibboleth" target="_blank">https://localhost:8443/idp/shibboleth</a>) Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (::1)<br><br></div><div style="font-size:12.8px">Any help would be welcome!<br></div><div style="font-size:12.8px">Thanks again,<br></div><div style="font-size:12.8px">Kind Regards,<br></div><div style="font-size:12.8px">Yasser<br></div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On 22 January 2016 at 17:00,  <span dir="ltr"><<a href="mailto:users-request@shibboleth.net" target="_blank">users-request@shibboleth.net</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Send users mailing list submissions to<br>
        <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
<br>
To subscribe or unsubscribe via the World Wide Web, visit<br>
        <a href="http://shibboleth.net/mailman/listinfo/users" rel="noreferrer" target="_blank">http://shibboleth.net/mailman/listinfo/users</a><br>
or, via email, send a message with subject or body 'help' to<br>
        <a href="mailto:users-request@shibboleth.net">users-request@shibboleth.net</a><br>
<br>
You can reach the person managing the list at<br>
        <a href="mailto:users-owner@shibboleth.net">users-owner@shibboleth.net</a><br>
<br>
When replying, please edit your Subject line so it is more specific<br>
than "Re: Contents of users digest..."<br>
<br>
<br>
Today's Topics:<br>
<br>
   1. Re: 'Deep linking' in Shibboleth (Cantor, Scott)<br>
   2. configuring soap back-channel on tomcat (Yasser Afifi)<br>
   3. Re: configuring soap back-channel on tomcat (Cantor, Scott)<br>
<br>
<br>
----------------------------------------------------------------------<br>
<br>
Message: 1<br>
Date: Fri, 22 Jan 2016 14:51:28 +0000<br>
From: "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>><br>
To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
Subject: Re: 'Deep linking' in Shibboleth<br>
Message-ID: <<a href="mailto:0733144C-9110-49BA-86EF-971CA2A851EA@osu.edu">0733144C-9110-49BA-86EF-971CA2A851EA@osu.edu</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
On 1/22/16, 9:48 AM, "users on behalf of Zico" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:mailzico@gmail.com">mailzico@gmail.com</a>> wrote:<br>
<br>
<br>
<br>
>Thanks Eric for your great description!<br>
>So.. what I can understand .. there is actually nothing to do from IDP side to facilitate deep linking.<br>
<br>
Nothing that isn't already required by SAML. That doesn't mean there aren't broken IdPs that don't support the standard fully, so I wouldn't say there's nothing the IdP has to do.<br>
<br>
-- Scott<br>
<br>
<br>
------------------------------<br>
<br>
Message: 2<br>
Date: Fri, 22 Jan 2016 16:29:37 +0000<br>
From: Yasser Afifi <<a href="mailto:yasser@3dissue.com">yasser@3dissue.com</a>><br>
To: <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
Subject: configuring soap back-channel on tomcat<br>
Message-ID:<br>
        <CAC=Xfo+39Gu+K0dK_yHv+3igS=8bXfFJ-b28Cyi8n2=<a href="mailto:jm3kzAg@mail.gmail.com">jm3kzAg@mail.gmail.com</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
Hello again,<br>
<br>
I am trying to configure tomcat for SOAP endpoints as per instruction in<br>
this wiki:<br>
<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPApacheTomcatPrepare" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPApacheTomcatPrepare</a><br>
<br>
but tomcat won't start listening on port 8443 once i enter this<br>
configuration. I am also guessing there is a mismatch between the tomcat<br>
certificate and the certificate on the idp-metadata.xml but i am not sure<br>
how to match them because i get this error:<br>
SSL certificate problem: application verification failure<br>
My SP can't verify tomcat certificate for some reason. Tomcat certificate<br>
is different from the one in the idp-metadata. But in the same time i can't<br>
configure tomcat to use the certificate in the idp as per instruction in<br>
the link above<br>
<br>
Any suggestions?<br>
<br>
Kindest Regards,<br>
Yasser<br>
-------------- next part --------------<br>
An HTML attachment was scrubbed...<br>
URL: <<a href="http://shibboleth.net/pipermail/users/attachments/20160122/708b0076/attachment-0001.html" rel="noreferrer" target="_blank">http://shibboleth.net/pipermail/users/attachments/20160122/708b0076/attachment-0001.html</a>><br>
<br>
------------------------------<br>
<br>
Message: 3<br>
Date: Fri, 22 Jan 2016 16:36:16 +0000<br>
From: "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>><br>
To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
Subject: Re: configuring soap back-channel on tomcat<br>
Message-ID: <<a href="mailto:9A148425-AFCE-41DE-B0F3-23BF8A466BC6@osu.edu">9A148425-AFCE-41DE-B0F3-23BF8A466BC6@osu.edu</a>><br>
Content-Type: text/plain; charset="utf-8"<br>
<br>
On 1/22/16, 11:29 AM, "users on behalf of Yasser Afifi" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:yasser@3dissue.com">yasser@3dissue.com</a>> wrote:<br>
<br>
<br>
<br>
>I am trying to configure tomcat for SOAP endpoints as per instruction in this wiki:<br>
><br>
><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPApacheTomcatPrepare" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPApacheTomcatPrepare</a><br>
<br>
1. Are you running V3 or V2? If V2, stop it. If V3, that's not the right page.<br>
<br>
2. Why are you using the back channel? Why do you think you need to? Did you review the documentation explaining why you would or wouldn't need it?<br>
<br>
-- Scott<br>
<br>
<br>
------------------------------<br>
<br>
Subject: Digest Footer<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
<br>
------------------------------<br>
<br>
End of users Digest, Vol 55, Issue 115<br>
**************************************<br>
</blockquote></div><br></div>