<div dir="ltr"><div><div><div>Hi,<br><br></div>I'm running Shibboleth IdP v3.2.1 and trying to set things up to work with a vendor (iModules) SP.<br><br></div>In the logs I see that it's "Unable to resolve outbound message endpoint". Digging deeper I see that the assertion URL in their metadata file and in the SAML request differ in the latter has &gid=1 appended to the end.<br><br></div>I saw a couple other schools wrote to this list when upgrading to IdPv3 and that's when I learned about the skipEndpointValidationWhenSigned flag. I tried applying this to the relying party and in the logs it does say <br><div><br> Message Handler: Validation of protocol message signature succeeded, message type: {urn:oasis:names:tc:SAML:2.0:protocol}AuthnRequest<br><br></div><div>But then it still goes on to the EndpointResolutionFailed part.<br><br></div><div>I will attempt to convey to the vendor that their URLs don't match, but is there any other way, even as a temporary measure, I can get this to work?<br><br></div><div>Note: Their metadata file is in InCommon so I don't think I could even edit it if I wanted to "fix" it for them.<br><br></div><div>Suggestions?<br></div><div><br></div><div>Thanks,<br></div><div>Ian<br clear="all"></div><div><div><div><div><br>-- <br><div class="gmail_signature">Ian Rifkin '04, MS '09<br>Software Systems Manager<br>Library and Technology Services (LTS)<br>Brandeis University<br><br><a href="http://go.brandeis.edu/u:irifkin" target="_blank">http://go.brandeis.edu/u:irifkin</a></div>
</div></div></div></div></div>