<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">Hello everyone,<br class=""><br class="">I’ve been tasked with setting up SAML with my organization’s implementation of CloudFoundry’s UAA (User Account and Authentication Server) and test it using TestShib. Unfortunately, I’m not very familiar with how these technologies work, so I’m having some trouble debugging.<br class=""><br class="">I’ve already registered our metadata file (attached) with TestShib and now after navigating to my organization’s login page, clicking the external TestShib login link, and logging in via TestShib, I get the following error:<br class=""><br class=""><blockquote style="margin: 0 0 0 40px; border: none; padding: 0px;" class=""><i class="">“No peer endpoint available to which to send SAML response”</i></blockquote><br class="">When looking at the TestShib logs, I see the following error (full log attached):<br class=""><br class=""><blockquote style="margin: 0 0 0 40px; border: none; padding: 0px;" class=""><i class="">10:44:02.683 - ERROR [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:447] - No return endpoint available for relying party cloudfoundry-saml-login</i></blockquote><div class=""><br class=""></div><div class="">I did some digging on the internet as well as the archived Shibboleth mailing lists, and nothing I tried seemed to solve this. As far as I can tell, the ACS endpoints seem to match up and they’re referring to the correct address.</div><div class=""><br class=""></div><div class="">Any idea what I might be doing wrong? Let me know if you need more information!</div><div class=""><br class=""></div><div class="">Thanks,</div><div class=""><br class=""></div><div class="">John</div><div class=""><br class=""></div></body></html>