<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
        {font-family:"\@SimSun";
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:"Lucida Console";
        panose-1:2 11 6 9 4 5 4 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
        {mso-style-priority:99;
        mso-style-link:"Plain Text Char";
        margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.PlainTextChar
        {mso-style-name:"Plain Text Char";
        mso-style-priority:99;
        mso-style-link:"Plain Text";
        font-family:"Calibri",sans-serif;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:297300132;
        mso-list-type:hybrid;
        mso-list-template-ids:1702531868 134807569 134807577 134807579 134807567 134807577 134807579 134807567 134807577 134807579;}
@list l0:level1
        {mso-level-text:"%1\)";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l0:level2
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l0:level3
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l0:level4
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l0:level5
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l0:level6
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l0:level7
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l0:level8
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l0:level9
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l1
        {mso-list-id:1735393785;
        mso-list-type:hybrid;
        mso-list-template-ids:204140592 134807569 134807577 134807579 134807567 134807577 134807579 134807567 134807577 134807579;}
@list l1:level1
        {mso-level-text:"%1\)";
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l1:level2
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l1:level3
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l1:level4
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l1:level5
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l1:level6
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l1:level7
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l1:level8
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-18.0pt;}
@list l1:level9
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
ol
        {margin-bottom:0cm;}
ul
        {margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-GB" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoPlainText">Thank Tom,<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">We actually use a connection over TLS , having exchanged our public certificate with the IDP for the AttributeQuery request, and this was working fine in our respective QA environments. The binding was occurring over port 9443 and the
 section of the IDP Metadata for attribute query on the SP side is as follow<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">AttributeAuthorityDescriptor for the QA environment:<o:p></o:p></p>
<table class="MsoTableGrid" border="1" cellspacing="0" cellpadding="0" style="border-collapse:collapse;border:none">
<tbody>
<tr>
<td width="623" valign="top" style="width:467.5pt;border:solid windowtext 1.0pt;padding:0cm 5.4pt 0cm 5.4pt">
<p class="MsoPlainText"><md:EntityDescriptor (…)<o:p></o:p></p>
<p class="MsoPlainText">(…)<o:p></o:p></p>
<p class="MsoPlainText"><md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"><o:p></o:p></p>
<p class="MsoPlainText">                                                <md:KeyDescriptor><o:p></o:p></p>
<p class="MsoPlainText">                                                                <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><o:p></o:p></p>
<p class="MsoPlainText">                                                                                <ds:X509Data><o:p></o:p></p>
<p class="MsoPlainText">                                                                                                <ds:X509Certificate><o:p></o:p></p>
<p class="MsoPlainText"><span lang="IT">CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE<o:p></o:p></span></p>
<p class="MsoPlainText"><span lang="IT">CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE
<o:p></o:p></span></p>
<p class="MsoPlainText"><span lang="IT">CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE
<o:p></o:p></span></p>
<p class="MsoPlainText"><span lang="IT">CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE
<o:p></o:p></span></p>
<p class="MsoPlainText"><span lang="IT">CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE
<o:p></o:p></span></p>
<p class="MsoPlainText"><span lang="IT">CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE CERTIFICATE
<o:p></o:p></span></p>
<p class="MsoPlainText"><span lang="IT"></ds:X509Certificate><o:p></o:p></span></p>
<p class="MsoPlainText"><span lang="IT">                                                                               
</span></ds:X509Data><o:p></o:p></p>
<p class="MsoPlainText">                                                                </ds:KeyInfo><o:p></o:p></p>
<p class="MsoPlainText">                                                </md:KeyDescriptor><o:p></o:p></p>
<p class="MsoPlainText">                                                <md:AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://qa-idp.domain:9443/idp/attrsvc.ssaml2"/><o:p></o:p></p>
<p class="MsoPlainText">                                                <md:AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://qa-idp.domain:9443/idp/attrsvc.ssaml2"/><o:p></o:p></p>
<p class="MsoPlainText">                                                <md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat><o:p></o:p></p>
<p class="MsoPlainText">                <span lang="DE"><md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat><o:p></o:p></span></p>
<p class="MsoPlainText"><span lang="DE">                                </span></md:AttributeAuthorityDescriptor><o:p></o:p></p>
<p class="MsoPlainText">(…)<o:p></o:p></p>
<p class="MsoPlainText"></md:EntityDescriptor><o:p></o:p></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoPlainText">This was working absolutely fine, even after removing the <md:KeyDescriptor>**. I suspect because we are using a non-default port (i.e. other than 443), as stated in the note on this page (<span style="color:#003300"><a href="https://wiki.shibboleth.net/confluence/display/IDP30/SAML2AttributeQueryConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/SAML2AttributeQueryConfiguration</a>)<o:p></o:p></span></p>
<p class="MsoPlainText"><span style="color:#003300"><o:p> </o:p></span></p>
<p class="MsoPlainText"><span style="color:#003300">** We tried to remove it to check if it was still working. The reason was that for the production IDP we were not provided with any KeyDescriptor element either.</span><o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">THEN WE MOVE TO PRODUCTION RELEASE<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">Then we were using the following metadata initially for the production IDP<o:p></o:p></p>
<table class="MsoTableGrid" border="1" cellspacing="0" cellpadding="0" style="border-collapse:collapse;border:none">
<tbody>
<tr>
<td width="623" valign="top" style="width:467.5pt;border:solid windowtext 1.0pt;padding:0cm 5.4pt 0cm 5.4pt">
<p class="MsoPlainText"><md:EntityDescriptor (…)<o:p></o:p></p>
<p class="MsoPlainText">(…)<o:p></o:p></p>
<p class="MsoPlainText"><md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"><o:p></o:p></p>
<p class="MsoPlainText">                                                <md:AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.domain/idp/attrsvc.ssaml2"/>                                       <md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat><o:p></o:p></p>
<p class="MsoPlainText">                <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat><o:p></o:p></p>
<p class="MsoPlainText">                                </md:AttributeAuthorityDescriptor><o:p></o:p></p>
<p class="MsoPlainText">(…)<o:p></o:p></p>
<p class="MsoPlainText"></md:EntityDescriptor><o:p></o:p></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">With this setup, we were getting the error <span style="font-size:8.5pt;font-family:"Lucida Console"">
HTTP/1.1 401 "SOAP client request not properly authenticated. SAML message Issuer=(SP) :::
<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__sdauth.sciencedirect.com_&d=DwMGaQ&c=9fZnZOgPWmHmvevlab4V4DSjtBMjorSlbQYfK_MauDg&r=MZGJbzAhCaLlmrt9tbpOJ3A09ZiEtpJF4NTACWTkEx4&m=_r64VGnOR4XtV6O1d6uLbb9iFU3BZDRZNpyPMOs9GxU&s=BXUlVOEM6ZnCwu_XWPYqV7XmC20qX6UXqJxXFJ2Yum4&e=">
<span style="color:blue">https://sdauth.sciencedirect.com/</span></a>. Authenticated identity=null"</span><span style="color:#1F497D">).
<o:p></o:p></span></p>
<p class="MsoPlainText"><span style="color:#1F497D">Highlighting clearly some authentication / certificate or signature issue  - not 100% sure what the trigger is here.<o:p></o:p></span></p>
<p class="MsoPlainText"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoPlainText"><span style="color:#1F497D">Subsequently we tried the following metadata
</span>for the production IDP (attempting to repeat access via port 9443)<o:p></o:p></p>
<table class="MsoTableGrid" border="1" cellspacing="0" cellpadding="0" style="border-collapse:collapse;border:none">
<tbody>
<tr>
<td width="623" valign="top" style="width:467.5pt;border:solid windowtext 1.0pt;padding:0cm 5.4pt 0cm 5.4pt">
<p class="MsoPlainText"><md:EntityDescriptor (…)<o:p></o:p></p>
<p class="MsoPlainText">(…)<o:p></o:p></p>
<p class="MsoPlainText"><md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"><o:p></o:p></p>
<p class="MsoPlainText">                                                <md:AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.domain:9443/idp/attrsvc.ssaml2"/>                                           <md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat><o:p></o:p></p>
<p class="MsoPlainText">                <span lang="DE"><md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat><o:p></o:p></span></p>
<p class="MsoPlainText"><span lang="DE">                                </span></md:AttributeAuthorityDescriptor><o:p></o:p></p>
<p class="MsoPlainText">(…)<o:p></o:p></p>
<p class="MsoPlainText"></md:EntityDescriptor><o:p></o:p></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoPlainText"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoPlainText"><span style="color:#1F497D">The error we are getting now is a server HTTP 500:<o:p></o:p></span></p>
<p class="MsoPlainText"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">HTTP/1.1 500 Server Error<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">Date: Wed, 22 Nov 2017 16:15:20 GMT<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">Content-Security-Policy: referrer origin<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">Cache-Control: no-cache, no-store<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">Pragma: no-cache<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">Expires: Thu, 01 Jan 1970 00:00:00 GMT<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">Content-Type: text/xml;charset=utf-8<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">Set-Cookie: PF=WeEOsMOySt2lQs3OPBkZnh;Path=/;Secure;HttpOnly<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">Transfer-Encoding: chunked<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console""><o:p> </o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">171<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console""><S11:Envelope xmlns:S11="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>"><S11:Body><S11:Fault><faultcode
 xmlns:soapenv="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>">soapenv:Server</faultcode><faultstring><span style="background:yellow;mso-highlight:yellow">Incoming binding urn:oasis:names:tc:SAML:2.0:bindings:SOAP
 is not enabled for (SP) :::</span> <a href="https://sdauth.sciencedirect.com/%3c/faultstring%3e%3c/S11:Fault%3e%3c/S11:Body%3e%3c/S11:Envelope">
<span style="color:blue">https://sdauth.sciencedirect.com/</faultstring></S11:Fault></S11:Body></S11:Envelope</span></a>><o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console"">0<o:p></o:p></span></p>
<p class="MsoNormal" style="text-autospace:none"><span style="font-size:8.5pt;font-family:"Lucida Console""><o:p> </o:p></span></p>
<p class="MsoPlainText"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoPlainText"><span style="color:#1F497D">We suspect that we should be able to sort this out by adjusting the IDP configuration. But our issue is still on-going…<o:p></o:p></span></p>
<p class="MsoPlainText"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoPlainText"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">Cheers,<o:p></o:p></p>
<p class="MsoPlainText">Christian.<o:p></o:p></p>
<p class="MsoPlainText"><span lang="FR"><o:p> </o:p></span></p>
<p class="MsoPlainText">-----Original Message-----<o:p></o:p></p>
<p class="MsoPlainText">From: users [mailto:users-bounces@shibboleth.net] On Behalf Of Tom Scavo<o:p></o:p></p>
<p class="MsoPlainText">Sent: 22 November 2017 14:43<o:p></o:p></p>
<p class="MsoPlainText">To: Shib Users <users@shibboleth.net><o:p></o:p></p>
<p class="MsoPlainText">Subject: Re: Incoming binding urn:oasis:names:tc:SAML:2.0:bindings:SOAP is not enabled for (SP) :::<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">*** External email: use caution ***<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">On Wed, Nov 22, 2017 at 9:32 AM, Pruvost, Christian (ELS-OXF) <c.pruvost@elsevier.com> wrote:<o:p></o:p></p>
<p class="MsoPlainText">> Yes, that's what I mean. But I think the answer I received directly clearly point to what I suspected.<o:p></o:p></p>
<p class="MsoPlainText">> A misconfiguration in SP metadata for that IDP  or the IDP not being configured for such binding with our SP...<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">The latter is very likely in my experience. IdPs routinely publish AttributeService endpoints (and other back-channel endpoints) that are untested and in some cases obviously broken.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">Since SP metadata does not indicate whether the SP is willing or able to send an AttributeQuery, SP metadata is not the issue here. The only thing you need in metadata is a signing key, which is used by your SOAP client to authenticate
 to the IdP.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">> (...)<o:p></o:p></p>
<p class="MsoPlainText">> as the error message says, the IdP doesn't have a SOAP endpoint
<o:p></o:p></p>
<p class="MsoPlainText">> location for the SP -  check your SP metadata etc to ensure you have
<o:p></o:p></p>
<p class="MsoPlainText">> one existing and then ensure that the IdP has that line entry for your
<o:p></o:p></p>
<p class="MsoPlainText">> SP entity - this will have to be done for every IdP (which is where
<o:p></o:p></p>
<p class="MsoPlainText">> federations come in useful as you just update your metadata in the
<o:p></o:p></p>
<p class="MsoPlainText">> main metadata file and all IdPs get updated<o:p></o:p></p>
<p class="MsoPlainText">> (...)<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">That makes no sense.<o:p></o:p></p>
<p class="MsoPlainText"><o:p> </o:p></p>
<p class="MsoPlainText">Tom<o:p></o:p></p>
<p class="MsoPlainText">--<o:p></o:p></p>
<p class="MsoPlainText">For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg<o:p></o:p></p>
<p class="MsoPlainText">To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<o:p></o:p></p>
</div>
<style>P {margin:0cm:margin-bottomL.0001pt;}</style><br>
<hr>
<p><span style="font-size:10pt;font-family:"Arial","sans-serif"">Elsevier Limited. Registered Office: The Boulevard, Langford Lane, Kidlington, Oxford, OX5 1GB, United Kingdom, Registration No. 1982084, Registered in England and Wales.</span>
<br clear="none">
</p>
</body>
</html>