<div dir="ltr">Try removing the "<NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat>" from the metadata.<div><br></div><div>I do not have this line in my config, and IIRC, removing that line is what got Carl's installation working.</div><div><br></div><div>ajs</div></div><br><div class="gmail_quote"><div dir="ltr">On Thu, May 17, 2018 at 3:14 PM Norman Bodnar <<a href="mailto:bodnarn@gmail.com">bodnarn@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Apologies ahead of time for my newness to this board. I'm starting a new thread based on the recent one for Netpartner/Shibboleth IdP3...<div><br></div><div>Note: new IdP3 server is successfully working with other service providers.</div><div><br><div><br></div><div>My scenario, new netpartner server, new shibboleth server (IdP3, previously our old netpartner worked with IdP2 server).<br><div><br></div><div>I've tried to apply the recent recommendations on this maillist, but I can never get to my shibboleth logon page. After hitting <a href="https://mynetpartnerserver/NetPartnerStudent" target="_blank">https://mynetpartnerserver/NetPartnerStudent</a>, the SAML goes across but after shibboleth gets it I get directed to a shib page:</div><div><br></div><div><br></div><div>The login service was unable to identify a compatible way to respond to the requested application. This is generally due to a misconfiguration on the part of the application and should be reported to the application's support team or owner. <br></div></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div>The logs show issue starting here (server names scrubbed)...</div><div><br></div><div><div>2018-05-17 15:19:26,883 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:65] - Profile Action SelectProfileInterceptorFlow: Moving completed flow intercept/security-policy/saml2-sso to completed set, selecting next one</div><div>2018-05-17 15:19:26,884 - DEBUG [net.shibboleth.idp.profile.interceptor.impl.SelectProfileInterceptorFlow:80] - Profile Action SelectProfileInterceptorFlow: No flows available to choose from</div><div>2018-05-17 15:19:26,895 - DEBUG [net.shibboleth.idp.saml.profile.impl.InitializeOutboundMessageContext:149] - Profile Action InitializeOutboundMessageContext: Initialized outbound message context</div><div>2018-05-17 15:19:26,918 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:375] - Profile Action PopulateBindingAndEndpointContexts: Attempting to resolve endpoint of type {urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService for outbound message</div><div>2018-05-17 15:19:26,920 - DEBUG [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:516] - Profile Action PopulateBindingAndEndpointContexts: Populating template endpoint for resolution from SAML AuthnRequest</div><div>2018-05-17 15:19:26,921 - WARN [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:410] - Profile Action PopulateBindingAndEndpointContexts: Unable to resolve outbound message endpoint for relying party 'NetPartner': EndpointCriterion [type={urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService, Binding=urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST, Location=<a href="https://servernamehere/NetPartnerStudent/Logon.aspx" target="_blank">https://servernamehere/NetPartnerStudent/Logon.aspx</a>, trusted=false]</div><div>2018-05-17 15:19:26,938 - WARN [org.opensaml.profile.action.impl.LogEvent:105] - A non-proceed event occurred while processing the request: EndpointResolutionFailed</div><div><br></div><div><br></div><div>From my Firefox developer tools, I see this:</div><div><br></div><div> HTTP400: BAD REQUEST - The request could not be processed by the server due to invalid syntax.</div><div>GET - <a href="https://shibbolethservernamehere/idp/profile/SAML2/Redirect/SSO?SAMLRequest=fZFBb8IwDIXv%2fIood1pAQmMRBTHQNCTGKlp22C00po1onS5OGfv3C93YkCYhJRfHee979nh6qkp2BEvaYMT7QY8zwMwojXnEt%2bljd8Snk86YZFXWYta4Ajfw3gA55j8iifYh4o1FYSRpEigrIOEykcyeV2IQ9ERtjTOZKTlbLiKO%2b6LYaY2q2h92kB2KfIdG1nWtKoA8xz3mgCpTnL1eqAZnqiVRA0skJ9H5Uq8%2f6vaG3f5d2r8X5zN84yz%2bcXrw8m2AW1i77yYST2kad%2bOXJG0FjlqBXfvuiK%2fBxdI6BHu2jyWRPvryXpYEnM2IwDoPODdITQU2AXvUGWw3q4gXztUkwtDTZhaUDqy3Kv0NQDXhn3DiGgXowpXJDQaS6hOfdBhr5y3ayPZq0LcDyQsQn%2fwZjMMrqV%2fpWpwTLhexKXX2yWZlaT7mFqTz8ZxtfDoW%2bq2H%2f9c%2b6XwB&RelayState=%2fNetPartnerStudent%2fDefault.aspx" target="_blank">https://shibbolethservernamehere/idp/profile/SAML2/Redirect/SSO?SAMLRequest=fZFBb8IwDIXv%2fIood1pAQmMRBTHQNCTGKlp22C00po1onS5OGfv3C93YkCYhJRfHee979nh6qkp2BEvaYMT7QY8zwMwojXnEt%2bljd8Snk86YZFXWYta4Ajfw3gA55j8iifYh4o1FYSRpEigrIOEykcyeV2IQ9ERtjTOZKTlbLiKO%2b6LYaY2q2h92kB2KfIdG1nWtKoA8xz3mgCpTnL1eqAZnqiVRA0skJ9H5Uq8%2f6vaG3f5d2r8X5zN84yz%2bcXrw8m2AW1i77yYST2kad%2bOXJG0FjlqBXfvuiK%2fBxdI6BHu2jyWRPvryXpYEnM2IwDoPODdITQU2AXvUGWw3q4gXztUkwtDTZhaUDqy3Kv0NQDXhn3DiGgXowpXJDQaS6hOfdBhr5y3ayPZq0LcDyQsQn%2fwZjMMrqV%2fpWpwTLhexKXX2yWZlaT7mFqTz8ZxtfDoW%2bq2H%2f9c%2b6XwB&RelayState=%2fNetPartnerStudent%2fDefault.aspx</a></div></div><div><br></div><div><br></div><div><br></div><div>My shibboleth configurations are as follows (relevant netpartner items only):</div><div><br></div><div><div>netpartner metadata</div><div><br></div><div><EntityDescriptor entityID="NetPartner" xmlns="urn:oasis:names:tc:SAML:2.0:metadata"></div><div> <SPSSODescriptor</div><div> protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol</div><div> urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"></div><div> <NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat></div><div> <AssertionConsumerService index="1"</div><div> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"</div><div> Location="<a href="https://servernamehere/NetPartner/NetPartnerStudent/Logon.aspx" target="_blank">https://servernamehere/NetPartner/NetPartnerStudent/Logon.aspx</a>"/></div><div> </SPSSODescriptor></div><div></EntityDescriptor></div><div><br></div><div><br></div><div>metadata-providers.xml </div><div><br></div><div><MetadataProvider id="NetPartnerMetadata"</div><div> xsi:type="FilesystemMetadataProvider"</div><div> xmlns="urn:mace:shibboleth:2.0:metadata"</div><div> metadataFile="%{idp.home}/metadata/netpartner.xml"/></div><div><br></div><div><br></div><div>relying-party.xml</div><div><br></div><div><bean id="SHA1SecurityConfig" parent="shibboleth.DefaultSecurityConfiguration"</div><div> p:signatureSigningConfiguration-ref="shibboleth.SigningConfiguration.SHA1" /></div><div><br></div><div>Under RelyingPartyOverrides</div><div><br></div><div><bean parent="RelyingPartyByName" c:relyingPartyIds="NetPartner"></div><div> <property name="profileConfigurations"></div><div> <list></div><div> <bean parent="Shibboleth.SSO" p:securityConfiguration-ref="SHA1SecurityConfig" /></div><div> <bean parent="SAML1.AttributeQuery" p:securityConfiguration-ref="SHA1SecurityConfig" /></div><div> <bean parent="SAML1.ArtifactResolution" p:securityConfiguration-ref="SHA1SecurityConfig" /></div><div> <bean parent="SAML2.ECP" p:securityConfiguration-ref="SHA1SecurityConfig" /></div><div> <bean parent="SAML2.Logout" p:securityConfiguration-ref="SHA1SecurityConfig" /></div><div> <bean parent="SAML2.AttributeQuery" p:securityConfiguration-ref="SHA1SecurityConfig" /></div><div> <bean parent="SAML2.ArtifactResolution" p:securityConfiguration-ref="SHA1SecurityConfig" /></div><div> <bean parent="SAML2.SSO"</div><div> p:encryptAssertions="false"</div><div> p:securityConfiguration-ref="SHA1SecurityConfig"</div><div> p:nameIDFormatPrecedence="#{{'urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified'}}" /></div><div> </list></div><div> </property></div><div></bean></div><div><br></div></div><div><br></div><div>On NetPartner login tab:</div><div><br></div><div>SSO: yes</div><div>Identity provider url: https:/myshibserver/idp/profile/SAML2/Redirect/SSO</div><div>Protocol binding: Post</div><div>Request nameid format: [Do Not Use]</div><div>Service Provider Name: NetPartner</div><div><br></div><div><br></div><div><br></div><div>Any help GREATLY appreciated.</div><div>-Norm Bodnar</div><div><br></div><div><br></div><div><br></div><div><br></div></div></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><b>Tony Skalski</b></div><div dir="ltr">System Administrator | IT</div><div dir="ltr"><img src="https://docs.google.com/uc?export=download&id=0B8pehFb2jk1VTlJUMXNxQzlUZ0k&revid=0B8pehFb2jk1VR0ZGVzBjRksvU1NMQUdwSzNIa05Ea08ydjFFPQ" width="200" height="77"><br></div><div dir="ltr"><b>Office: </b><a href="javascript:void(0);" target="_blank">507-786-3227</a></div><div dir="ltr">1510 St. Olaf Avenue Northfield, MN 55057</div><div dir="ltr"><a href="http://stolaf.edu" target="_blank">stolaf.edu</a></div><div><div><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div>