<div dir="ltr">Thanks for the reply Joseph Fischetti,<div> Our SP redirects to<b> https.</b></div><div> I guess it will load the IDP's SSO url from the metadata file. In the metadata the url will be like <a href="https://test.shibbolethidp.test.com/idp/..">https://test.shibbolethidp.test.com/idp/..</a>..<br> Kindly let me know whether I am looking into the correct configuration...</div><div><br></div><div>Thanks,</div><div>Satheesh </div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Aug 22, 2017 at 8:32 AM, Joseph Fischetti <span dir="ltr"><<a href="mailto:Joseph.Fischetti@marist.edu" target="_blank">Joseph.Fischetti@marist.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="m_4523089533765804864socmaildefaultfont" dir="ltr" style="font-family:Arial,Helvetica,sans-serif;font-size:10.5pt">
<div dir="ltr">Satheesh,</div>

<div dir="ltr"> </div>

<div dir="ltr">Did you configure the SP to redirect to http, or https?  </div>

<div dir="ltr"> </div>

<div dir="ltr"> </div>

<div dir="ltr">
<div class="m_4523089533765804864socmaildefaultfont" dir="ltr" style="font-family:Arial,Helvetica,sans-serif;font-size:10.5pt">
<div class="m_4523089533765804864socmaildefaultfont" dir="ltr" style="font-family:Arial,Helvetica,sans-serif;font-size:10.5pt">
<div dir="ltr">
<div style="font-size:12pt;font-weight:bold;font-family:sans-serif"><font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2"><font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2"><font color="#7c7c5f">Joseph Fischetti</font></font></font></div>

<div style="font-size:10pt;font-weight:bold;font-family:sans-serif"><font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2"><font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2">Linux System Administrator</font></font></div>

<div style="font-size:10pt;font-weight:bold;font-family:sans-serif"><font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2"><font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2">Marist College</font></font></div>

<div style="font-size:8pt;font-family:sans-serif;margin-top:10px">
<div><font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2"><font face="Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size="2"><span style="font-weight:bold"><font color="#336699">E-mail: </font></span><a href="mailto:joseph.fischetti@marist.edu" target="_blank"><font color="#555555">joseph.fischetti@marist.edu</font></a></font></font></div>
</div>
</div>
</div>
</div>
</div>

<div dir="ltr"> </div>

<div dir="ltr"> </div>

<blockquote dir="ltr" style="border-left:solid #aaaaaa 2px;margin-left:5px;padding-left:5px;direction:ltr;margin-right:0px"><div><div class="h5">----- Original message -----<br>
From: Satheesh Kumar <<a href="mailto:satheeshvsbk@gmail.com" target="_blank">satheeshvsbk@gmail.com</a>><br>
Sent by: "users" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>><br>
To: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Cc:<br>
Subject: destination endpoint did not match the recipient endpoint error<br>
Date: Tue, Aug 22, 2017 8:23 AM<br>
 
<div dir="ltr"> 
<div>Hi all,</div>

<div>      I am trying to access my test IDPv3.3 via apache proxy through AJP port. When I do this I am getting below error: </div>

<div>    </div>

<div>       ERROR [org.opensaml.saml.common.<wbr>binding.security.impl.<wbr>ReceivedEndpointSecurityHandle<wbr>r:200] - Message Handler: <b> SAML message intended destination endpoint '<a href="https://testshibbolethidp.test.com/idp/profile/SAML2/Redirect/SSO" target="_blank">https://testshibbolethidp.<wbr>test.com/idp/profile/SAML2/<wbr>Redirect/SSO</a>' did not match the recipient endpoint '<a href="http://testshibbolethidp.test.com/idp/profile/SAML2/Redirect/SSO" target="_blank">http://testshibbolethidp.<wbr>test.com/idp/profile/SAML2/<wbr>Redirect/SSO</a>'</b></div>

<div>2017-08-22 12:03:37,577 - WARN [net.shibboleth.idp.profile.<wbr>impl.<wbr>WebFlowMessageHandlerAdaptor:<wbr>202] - Profile Action WebFlowMessageHandlerAdaptor: Exception handling message</div>

<div> </div>

<div>        <b>Tomcat connector details-server.xml:</b></div>

<div> <Connector  port="8010" maxThreads="50" minSpareThreads="5" connectionTimeout="60000"  packetSize="[20000]"   protocol="AJP/1.3" redirectPort="8443" tomcatAuthentic</div>

<div>ation="false"/></div>

<div>  <Connector port="8443" protocol="HTTP/1.1" SSLEnabled="true" maxThreads="150" scheme="https" secure="true"  clientAuth="false" sslProtocol="TLS" keystoreFile="conf/</div>

<div>KeyStore.jks" keystorePass="password"/> </div>

<div>        </div>

<div>         <b>IDP's entity ID-taken from idp.properties file:</b></div>

<div>          </div>

<div> <a href="https://test-shibbolethidp.test.com/idp/shibboleth" target="_blank">https://test-shibbolethidp.<wbr>test.com/idp/shibboleth</a></div>

<div>  </div>

<div>          Kindly let me know, what I am missing in configuration.</div>

<div> </div>

<div>Thanks,<br>
Satheesh </div>

<div><br>
 </div>
</div>

</div></div><span class="HOEnZb"><font color="#888888"><div><font face="Default Monospace,Courier New,Courier,monospace" size="2">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.<wbr>net</a></font></div>
</font></span></blockquote>

<div dir="ltr"> </div>
</div>


<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature">*Best wishes*,<br>*Satheesh K*<br><br><br><br></div>
</div>