<div dir="ltr">Good spot - looks like it's the reverse proxy. I tried it on a server, with the IP address of the IdP fed into the hosts file, and it did the login process. Will ask the admin to fix that tomorrow.<div><br><div>I got an error at the SP end, which is probably a mistake by me, but at least Canvas has a good debugger which will watch your SAML attempts in realtime while you're configuring a SAML IdP with it.</div></div><div><br></div><div>Thanks both.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Jun 6, 2018 at 4:17 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> I checked the IdP logs too, no sign of errors there (or of it being hit to process<br>
> any attempt).<br>
<br>
</span>Either the error message is really Apache or a load balancer front-end or it's Jetty and the IdP isn't even running. Both cases are obvious from the look of the message and the logs.<br>
<span class="HOEnZb"><font color="#888888"> <br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>