<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:Consolas;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">I’m attempting UnsolicitedSSO and I’m different issues in both development and production:<o:p></o:p></p>
<p class="MsoNormal">in development the ACS I’m getting the following (perhaps the space in ?c=umb test)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">2016-08-30 12:36:39,254 - WARN [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:182] - Profile Action WebFlowMessageHandlerAdaptor: Exception handling message<o:p></o:p></p>
<p class="MsoNormal">org.opensaml.messaging.handler.MessageHandlerException: Could not obtain SAML destination endpoint URL from message context<o:p></o:p></p>
<p class="MsoNormal"> at org.opensaml.saml.common.binding.impl.SAMLOutboundDestinationHandler.doInvoke(SAMLOutboundDestinationHandler.java:66)<o:p></o:p></p>
<p class="MsoNormal">Caused by: org.opensaml.saml.common.binding.BindingException: The endpoint location http://webtma-dev.umaryland.edu/tmalogin/samlservice.aspx?c=umb test is not a valid URL<o:p></o:p></p>
<p class="MsoNormal"> at org.opensaml.saml.common.binding.SAMLBindingSupport.getEndpointURL(SAMLBindingSupport.java:145)<o:p></o:p></p>
<p class="MsoNormal">Caused by: java.net.URISyntaxException: Illegal character in query at index 63: http://webtma-dev.umaryland.edu/tmalogin/samlservice.aspx?c=umb test<o:p></o:p></p>
<p class="MsoNormal"> at java.net.URI$Parser.fail(URI.java:2848)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">production doesn’t have the space in the samlservice.aspx, it’s simply samlservice.aspx?c=umb<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I have the following in the relying-party.xml for version 2.x; I’m trying to convert to a 3.x. I’m hoping it’s simply replicating the signResponses=”always” but that seem to fail as well. Is this where the custom bean comes into play?
Any thoughts? Thanks<o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<pre>The application is reporting: <span style="font-family:"Courier New"">[SSOException: Failed to verify the XML signature.]<o:p></o:p></span></pre>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><RelyingParty id="webtma.umaryland.edu/sp" provider="https://webauth.umaryland.edu/idp/shibboleth"<o:p></o:p></p>
<p class="MsoNormal"> defaultSigningCredentialRef="IdPCredential"<o:p></o:p></p>
<p class="MsoNormal"> defaultAuthenticationMethod="urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport"><o:p></o:p></p>
<p class="MsoNormal"> <ProfileConfiguration xsi:type="saml:SAML2SSOProfile"<o:p></o:p></p>
<p class="MsoNormal"> signResponses="always" encryptAssertions="never"/><o:p></o:p></p>
<p class="MsoNormal"> <ProfileConfiguration xsi:type="saml:SAML2AttributeQueryProfile" /><o:p></o:p></p>
<p class="MsoNormal"> <ProfileConfiguration xsi:type="saml:SAML2ArtifactResolutionProfile" /><o:p></o:p></p>
<p class="MsoNormal"> </RelyingParty><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">--------------------------------------------<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"> <bean parent="RelyingPartyByName" c:relyingPartyIds="webtma.umaryland.edu/sp"><o:p></o:p></p>
<p class="MsoNormal"> <property name="profileConfigurations"><o:p></o:p></p>
<p class="MsoNormal"> <list><o:p></o:p></p>
<p class="MsoNormal"> <bean parent="SAML2.SSO" p:encryptAssertions="false" /><o:p></o:p></p>
<p class="MsoNormal"> </list><o:p></o:p></p>
<p class="MsoNormal"> </property><o:p></o:p></p>
<p class="MsoNormal"> </bean><o:p></o:p></p>
</div>
</body>
</html>