<div style="font: normal 13px Arial; color:rgb(0, 0, 0);">Hi,<br><br>I'm trying to configure shibboletth I fixed the redirect url but now I got a strange error.<br><br>On the idp I got the following log:<br> <br><div>2016-11-03 17:03:06,088 - DEBUG [org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:64] - Decoded RelayState: ss:mem:ea40c8a762fa9c38b14a864135f1815be9ffb3702bdc2c55e5ce7d149ad84303</div><div>2016-11-03 17:03:06,089 - DEBUG [org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:96] - Base64 decoding and inflating SAML message</div><div>2016-11-03 17:03:06,090 - DEBUG [org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:79] - Decoded SAML message</div><div>2016-11-03 17:03:06,091 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.CheckMessageVersionHandler' on INBOUND message context</div><div>2016-11-03 17:03:06,091 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div>2016-11-03 17:03:06,091 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.saml1.binding.impl.SAML1ArtifactRequestIssuerHandler' on INBOUND message context</div><div>2016-11-03 17:03:06,091 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div>2016-11-03 17:03:06,092 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLProtocolAndRoleHandler' on INBOUND message context</div><div>2016-11-03 17:03:06,093 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div>2016-11-03 17:03:06,093 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler' on INBOUND message context</div><div>2016-11-03 17:03:06,094 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div>2016-11-03 17:03:06,094 - DEBUG [org.opensaml.saml.metadata.resolver.impl.BasicRoleDescriptorResolver:198] - Metadata document did not contain a descriptor for entity http://sp.mysaml.org/Shibboleth.sso</div><div>2016-11-03 17:03:06,094 - DEBUG [org.opensaml.saml.metadata.resolver.impl.BasicRoleDescriptorResolver:281] - Metadata document did not contain any role descriptors of type {urn:oasis:names:tc:SAML:2.0:metadata}SPSSODescriptor for entity http://sp.mysaml.org/Shibboleth.sso</div><div>2016-11-03 17:03:06,094 - DEBUG [org.opensaml.saml.metadata.resolver.impl.BasicRoleDescriptorResolver:252] - Metadata document does not contain a role of type {urn:oasis:names:tc:SAML:2.0:metadata}SPSSODescriptor supporting protocol urn:oasis:names:tc:SAML:2.0:protocol for entity http://sp.mysaml.org/Shibboleth.sso</div><div>2016-11-03 17:03:06,094 - INFO [org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler:128] - Message Handler:  No metadata returned for http://sp.mysaml.org/Shibboleth.sso in role {urn:oasis:names:tc:SAML:2.0:metadata}SPSSODescriptor with protocol urn:oasis:names:tc:SAML:2.0:protocol</div><div>2016-11-03 17:03:06,095 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:154] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.saml.common.binding.impl.SAMLAddAttributeConsumingServiceHandler' on INBOUND message context</div><div>2016-11-03 17:03:06,095 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:175] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.AuthnRequestImpl'</div><div>2016-11-03 17:03:06,095 - DEBUG [org.opensaml.saml.common.binding.impl.SAMLAddAttributeConsumingServiceHandler:110] - Message Handler:  No metadata context found, nothing to do</div><div>2016-11-03 17:03:06,095 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeRelyingPartyContextFromSAMLPeer:132] - Profile Action InitializeRelyingPartyContextFromSAMLPeer: Attaching RelyingPartyContext based on SAML peer http://sp.mysaml.org/Shibboleth.sso</div><div>2016-11-03 17:03:06,096 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:293] - Resolving relying party configuration</div><div>2016-11-03 17:03:06,096 - DEBUG [net.shibboleth.idp.relyingparty.impl.DefaultRelyingPartyConfigurationResolver:299] - Profile request is unverified, returning configuration shibboleth.UnverifiedRelyingParty</div><div>2016-11-03 17:03:06,096 - DEBUG [net.shibboleth.idp.profile.impl.SelectRelyingPartyConfiguration:136] - Profile Action SelectRelyingPartyConfiguration: Found relying party configuration shibboleth.UnverifiedRelyingParty for request</div><div>2016-11-03 17:03:06,097 - WARN [net.shibboleth.idp.profile.impl.SelectProfileConfiguration:111] - Profile Action SelectProfileConfiguration: Profile http://shibboleth.net/ns/profiles/saml2/sso/browser is not available for relying party configuration shibboleth.UnverifiedRelyingParty</div><div>2016-11-03 17:03:06,097 - WARN [org.opensaml.profile.action.impl.LogEvent:76] - An error event occurred while processing the request: InvalidProfileConfiguration</div><span style="background-color: transparent;">2016-11-03 17:03:06,098 - DEBUG [org.opensaml.saml.common.profile.logic.DefaultLocalErrorPredicate:154] - No SAMLBindingContext or binding URI available, error must be handled locally</span> <br><br><br>Now the part that I can't Understand is why it complains about Metadata document did not contain a descriptor for entity http://sp.mysaml.org/Shibboleth.sso. when the returned metadata follows:<br><br> <br><div><div><!--</div><div>This is example metadata only. Do *NOT* supply it as is without review,</div><div>and do *NOT* provide it in real time to your partners.</div><div> --></div><div><md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_c76cd6d29798e4a6764fcb6c29d66697eb5d6ddf" entityID="http://sp.mysaml.org/Shibboleth.sso"></div><div><br></div><div>  <md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"></div><div>    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/></div><div>    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/></div><div>    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/></div><div>    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/></div><div>    <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/></div><div>    <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/></div><div>  </md:Extensions></div><div><br></div><div>  <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"></div><div>    <md:Extensions></div><div>      <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://sp.mysaml.org/Shibboleth.sso/Login"/></div><div>      <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://sp.mysaml.org/Shibboleth.sso/Login" index="1"/></div><div>    </md:Extensions></div><div>    <md:KeyDescriptor></div><div>      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"></div><div>        <ds:KeyName>wdgai04-6313.intranet.mae.dom</ds:KeyName></div><div>        <ds:X509Data></div><div>          <ds:X509SubjectName>CN=wdgai04-6313.intranet.mae.dom</ds:X509SubjectName></div><div>          <ds:X509Certificate>MIIEHjCCAoagAwIBAgIJAJ+tFZTSSMA1MA0GCSqGSIb3DQEBCwUAMCgxJjAkBgNV</div><div>BAMTHXdkZ2FpMDQtNjMxMy5pbnRyYW5ldC5tYWUuZG9tMB4XDTE2MTAyNzA5MzMx</div><div>OVoXDTI2MTAyNTA5MzMxOVowKDEmMCQGA1UEAxMdd2RnYWkwNC02MzEzLmludHJh</div><div>bmV0Lm1hZS5kb20wggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQDQlBWE</div><div>55ctDB+OBisqFeYMDIMEEhS4U9yzlVIQDvLclyIBlTv2fXV7U+WNEX9QBFr/CWHw</div><div>DHZf3abLWD5ihSQsYm6LMTdMOr0JizTpHo6lifMLTPdDIKmjJqBTnj523hNAWbHE</div><div>nlp50FdYQzMFtwO7Bck1WIhgRu+zLRhRZGgTCXt5U4hlOIVXatQgv0/XUe/o4jut</div><div>o/I8qf04v0i4gmE4wJkR46jB2pALpWUH6DSVwezoZ5++igPt7nr3N3mCnTghGkjI</div><div>e/PRvB0hBjTbR0jspLhJj+7K6L+HKZffmXdY4/dbfAodEqm+8ChPLXVDwTvB2fEX</div><div>d8t8b7/WIiL3pvaFOsj+Z4uUOejMGxpdvEuZCIFvHdv5Xhj7WlR+0JG31vRrCrzF</div><div>xv0plWnwxOqxIKAoeKLteV1VGPgqGfDBPS+VJmvry80X5iMOBX8vxWM/toIfHFUv</div><div>q0eb35PgrUzecb2OMkcTg0lUr8Ai1WuT8EuHpfICHkCidITGtWIgmzcUYEECAwEA</div><div>AaNLMEkwKAYDVR0RBCEwH4Idd2RnYWkwNC02MzEzLmludHJhbmV0Lm1hZS5kb20w</div><div>HQYDVR0OBBYEFJ+CPdKGHGvLw7rk9br8NxuVOWE8MA0GCSqGSIb3DQEBCwUAA4IB</div><div>gQCzbb699lDGjKS5JkOtq0XCnkcjLj/PnuFkrQEd5jBBO9y0a00l/Db6N7FEoif9</div><div>p1tYoN55AnSoNljDUlZ2NFt7ov7mOZCax6ema/rcv0KaFcql3mXdmsvQKsFBxU6U</div><div>mjFXk3f2DpyM1rOeZtSThbOSnqkHRwlC6pNxZOhEzOQQEv+EU+VDdk909fGch4IY</div><div>vCFnJVFztuPsw0zBFayE+yD7bAGbx7ZvXKUj0vnWYuPOY/DB8ZyIbaKl140JFt4d</div><div>808xZAosOKAHzMypqEOgDt0zMC2eg908Qrt1rT3cmh1NP4qdBNgwY0bYRhiIs0H8</div><div>nH9993UH9n7y23GsP7dxSetDUYYmMMNT48tO9xP0uftlB2brX0PuxcHOJQwTK744</div><div>tndNjpwfzKedEKqRt+e3D8YNl5q9O1J/3I2K+tYCjYj3UzrSaOFxPb6l4eUTJ557</div><div>dv/oiYZnfFAVhekCojlg0wTNTlETLZ8D45JGBRfs3WWhkwAuomzdx+AkbydRMgVu</div><div>2k4=</div><div></ds:X509Certificate></div><div>        </ds:X509Data></div><div>      </ds:KeyInfo></div><div>      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/></div><div>      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/></div><div>      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/></div><div>      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/></div><div>      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/></div><div>      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/></div><div>      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/></div><div>      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/></div><div>      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/></div><div>    </md:KeyDescriptor></div><div>    <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://sp.mysaml.org/Shibboleth.sso/Artifact/SOAP" index="1"/></div><div>    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://sp.mysaml.org/Shibboleth.sso/SLO/SOAP"/></div><div>    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://sp.mysaml.org/Shibboleth.sso/SLO/Redirect"/></div><div>    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://sp.mysaml.org/Shibboleth.sso/SLO/POST"/></div><div>    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://sp.mysaml.org/Shibboleth.sso/SLO/Artifact"/></div><div>    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://sp.mysaml.org/Shibboleth.sso/SAML2/POST" index="1"/></div><div>    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://sp.mysaml.org/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/></div><div>    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://sp.mysaml.org/Shibboleth.sso/SAML2/Artifact" index="3"/></div><div>    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://sp.mysaml.org/Shibboleth.sso/SAML2/ECP" index="4"/></div><div>    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://sp.mysaml.org/Shibboleth.sso/SAML/POST" index="5"/></div><div>    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://sp.mysaml.org/Shibboleth.sso/SAML/Artifact" index="6"/></div><div>  </md:SPSSODescriptor></div><div><br></div><div></md:EntityDescriptor></div></div><div><br><br>What's wrong?<br><br>Thanks in advance,<br><br>Rune </div><br><br>  </div>