<div dir="ltr">Acc'd to the SAML spec, the IDPSSODescriptor element must include at least one SingleSignOnService:<div><br></div><div><a href="https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf">https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf</a><br></div><div>2.4.3 Element <IDPSSODescriptor><br></div><div><div><SingleSignOnService> [One or More]</div><div>One or more elements of type EndpointType that describe endpoints that support the profiles of</div><div>the Authentication Request protocol defined in [SAMLProf]. All identity providers support at least</div><div>one such endpoint, by definition. The ResponseLocation attribute MUST be omitted.</div></div><div><br></div><div><br></div><div>Liam</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Dec 2, 2016 at 11:43 AM, Sam Jacob <span dir="ltr"><<a href="mailto:skjacob@gmail.com" target="_blank">skjacob@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">IDP provided their metadata file and it's missing the SingleSignOnService tag in the XML file.<div>and shib is giving an error: "metadata instance failed manual validation checking: IDPSSODescriptor must have at least one SingleSignOnService. "</div><div><br></div><div>is "SingleSignOnService" a required attribute?</div><div>Can SSO work without "SingleSignOnService" ?</div><div><br></div><div>thanks<span class="HOEnZb"><font color="#888888"><br clear="all"><div><br></div>-- <br><div class="m_-8395249915164514901gmail_signature">Sam Jacob</div>
</font></span></div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div>