<div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr">Hi,<div>Thank you very much for bearing with me. I fixed that error as you explained.</div><div>I am an University Undergraduate and I was asked to develop and ECP client as one of my projects. For that I was advised to use an existing client with Shibboleth IDP and examine how it works.</div><div> </div><div>Now my client works up to receiving response from the IDP .</div><div><br></div><div>This is the SP response</div><div>*******************************</div><div><div><S:Envelope xmlns:S="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>"></div><div><S:Header></div><div><paos:Request xmlns:paos="urn:liberty:paos:2003-08" S:actor="<a href="http://schemas.xmlsoap.org/soap/actor/next">http://schemas.xmlsoap.org/soap/actor/next</a>" S:mustUnderstand="1" responseConsumerURL="<a href="https://localhost/Shibboleth.sso/SAML2/ECP">https://localhost/Shibboleth.sso/SAML2/ECP</a>" service="urn:oasis:names:tc:SAML:2.0:profiles:SSO:ecp"/><ecp:Request xmlns:ecp="urn:oasis:names:tc:SAML:2.0:profiles:SSO:ecp" IsPassive="0" S:actor="<a href="http://schemas.xmlsoap.org/soap/actor/next">http://schemas.xmlsoap.org/soap/actor/next</a>" S:mustUnderstand="1"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://localhost/shibboleth">https://localhost/shibboleth</a></saml:Issuer><samlp:IDPList xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"><samlp:IDPEntry ProviderID="<a href="https://idp.shibboleth.com/idp/shibboleth">https://idp.shibboleth.com/idp/shibboleth</a>"/></samlp:IDPList></ecp:Request><ecp:RelayState xmlns:ecp="urn:oasis:names:tc:SAML:2.0:profiles:SSO:ecp" S:actor="<a href="http://schemas.xmlsoap.org/soap/actor/next">http://schemas.xmlsoap.org/soap/actor/next</a>" S:mustUnderstand="1">ss:mem:178ef6c111d4cdc0071469d3a1a1ea749169b90e197dfc8bfed254d27ae5d8de</ecp:RelayState></S:Header><S:Body><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="<a href="https://localhost/Shibboleth.sso/SAML2/ECP">https://localhost/Shibboleth.sso/SAML2/ECP</a>" ID="_dc9887ee19356552fcc1beca79a11163" IssueInstant="2018-08-30T03:48:07Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Version="2.0"></div><div><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://localhost/shibboleth">https://localhost/shibboleth</a></saml:Issuer></div><div><samlp:NameIDPolicy AllowCreate="1"/><samlp:Scoping><samlp:IDPList><samlp:IDPEntry ProviderID="<a href="https://idp.shibboleth.com/idp/shibboleth">https://idp.shibboleth.com/idp/shibboleth</a>"/></div><div></samlp:IDPList></samlp:Scoping></div><div></samlp:AuthnRequest></div><div></S:Body></div><div></S:Envelope></div></div><div><br></div><div><br></div><div>This is the IDP request</div><div>***********************************</div><div><div><S:Envelope xmlns:S="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>"></div><div><S:Body><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="<a href="https://localhost/Shibboleth.sso/SAML2/ECP">https://localhost/Shibboleth.sso/SAML2/ECP</a>" ID="_dc9887ee19356552fcc1beca79a11163" IssueInstant="2018-08-30T03:48:07Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://localhost/shibboleth">https://localhost/shibboleth</a></saml:Issuer></div><div><samlp:NameIDPolicy AllowCreate="1"/><samlp:Scoping></div><div><samlp:IDPList><samlp:IDPEntry ProviderID="<a href="https://idp.shibboleth.com/idp/shibboleth">https://idp.shibboleth.com/idp/shibboleth</a>"/></samlp:IDPList></div><div></samlp:Scoping></div><div></samlp:AuthnRequest></div><div></S:Body></div><div></S:Envelope></div></div><div><br></div><div>This is the IDP response</div><div>**************************************</div><div><div>?xml version="1.0" encoding="UTF-8"?> </div><div><soap11:Envelope xmlns:soap11="<a href="http://schemas.xmlsoap.org/soap/envelope/">http://schemas.xmlsoap.org/soap/envelope/</a>"><soap11:Header></div><div><ecp:Response AssertionConsumerServiceURL="<a href="https://localhost/Shibboleth.sso/SAML2/ECP">https://localhost/Shibboleth.sso/SAML2/ECP</a>" soap11:actor="<a href="http://schemas.xmlsoap.org/soap/actor/next">http://schemas.xmlsoap.org/soap/actor/next</a>" soap11:mustUnderstand="1" xmlns:ecp="urn:oasis:names:tc:SAML:2.0:profiles:SSO:ecp"/></soap11:Header><soap11:Body><saml2p:Response Destination="<a href="https://localhost/Shibboleth.sso/SAML2/ECP">https://localhost/Shibboleth.sso/SAML2/ECP</a>" ID="_6283e7bea940f33435211324bd96164b" InResponseTo="_dc9887ee19356552fcc1beca79a11163" IssueInstant="2018-08-30T03:48:11.154Z" Version="2.0" xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"></div><div><saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://idp.shibboleth.com/idp/shibboleth">https://idp.shibboleth.com/idp/shibboleth</a></saml2:Issuer></div><div><ds:Signature xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"> <ds:SignedInfo> </div><div><ds:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/> <ds:SignatureMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>"/></div><div> <ds:Reference URI="#_6283e7bea940f33435211324bd96164b"> </div><div><ds:Transforms> <ds:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/> <ds:Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/> </div><div></ds:Transforms> <ds:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>"/> <ds:DigestValue>5DrAN6876mNZg9RB09fX23beEILzdQ6PCv1xyyGNG0c=</ds:DigestValue> </div><div></ds:Reference></div><div> </ds:SignedInfo></div><div> <ds:SignatureValue> </div><div> buXfeeL0UxboNLznhcSxdImGlFSIpR+CVFQm7qql46q66EWTallyftwCQW/FdLSjqOVyek0wDlee </div><div> PdYLugfxNB574GFM0ReGDJPA9coFHUKXD828Yc+oHeZXIn/X9x8S065ToXWkd8/rN9UHpxVIUkee hixoDB5hw70AjuYscW977wOci8DHBsmPmPeUwPlTcNrJ+raSXU7Wq8mM06ktGMAzfTHZx4gam8c4 </div><div> 7EWuibVpp8U1BRav1AdovXi9SGtycmjRGsY+Zr8FVLAh1nF7nx591A6o8IaTadv9Xd015HAI0TXs gqoeR3UuV+OiuZ6aSK9R1vaCbrAPx9Dy9O994Q== </div><div> </ds:SignatureValue></div><div> <ds:KeyInfo></div><div> <ds:X509Data></div><div><ds:X509Certificate></div><div>MIIDMzCCAhugAwIBAgIUUAFRLb2Ue/ye+8+kOSK/QKH4yKswDQYJKoZIhvcNAQELBQAwHTEbMBkG </div><div>A1UEAwwSaWRwLnNoaWJib2xldGguY29tMB4XDTE4MDgwOTA5MDY1M1oXDTM4MDgwOTA5MDY1M1ow HTEbMBkGA1UEAwwSaWRwLnNoaWJib2xldGguY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB</div><div> CgKCAQEAupOQgM6h0AGOG8d3GRGYV41gaRERu72V2vSOXQKQExg4MzHHl8mAQFgKDRb4Y04U5cdo UJmUFb41jF39Hwfl3J9L//rcR2sHBt2gEwQj9HAmj9itQTKvjqEusMxbMh+e8DnE3GBReFN81Ndo </div><div> HhVpwo5tNCIdK4wNT0WLpCFyWoQtBdSMTtz+1v2pqb+hdhxBxh5KeOdJ1iGJxCqOlxv/VcDmc3F7 DahYW8GZZlKxGU37le5QkHiQDKK4Z5tS9KBTeBD9t1jjvlm08eYTxFBSCEV8UTeH/NON771GMD5A </div><div> +8kRgniNmokoVXWZgYRZXDXE6nI1QnIOLvEkunS4vX/K7QIDAQABo2swaTAdBgNVHQ4EFgQUPp5+ OsPqu06buO1yMNn6z1DnWLUwSAYDVR0RBEEwP4ISaWRwLnNoaWJib2xldGguY29thilodHRwczov </div><div> L2lkcC5zaGliYm9sZXRoLmNvbS9pZHAvc2hpYmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAIfmg h3ruHVa3pHWkX5xo68DceekztFSP64Pg98nceDSlsmP5NvuCnUIBTvFuPH5xdLjLsYhE0nygq7sC</div><div> AkCe2q1WXKhI842hjDzTBIhr4MSUwkl20kAXjH6NFj/IORf1mb2oKH4JtjlzCDPQrZWq/kbIG8rX P6lRYIZD+5NTkmukoUBBhv7AtqaaOkaFT9fslVUTHt/0Vm95pezyiU9wOniiPXt/2j+zKmw7OuvT</div><div> uxnRKVih4hmg8f1Bo/Im0P0GPe2f5dUUwlb1tlDub239VaDv99AsiTvaZ+4mvK0l2QleIsDWuTlK 9HfxYSwgTtwvL0VUF4PJZV3kDg2cqO+y9A==</ds:X509Certificate></div><div></ds:X509Data></ds:KeyInfo></div><div></ds:Signature></div><div><saml2p:Status><saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Responder"/></div><div><saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage></div><div></saml2p:Status></div><div></saml2p:Response></div><div></soap11:Body></div><div></soap11:Envelope></div></div><div><br></div><div>Could you please explain me whether this error happens due to failures in my ECP configuration in the IDP? Can you provide me some guidance to fix this.</div><div>Thank you for replying me.</div><div><br></div><div>winma</div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div></div></div></div></div><br><div class="gmail_quote"><div dir="ltr">On Wed, Aug 29, 2018 at 12:57 PM Peter Schober <<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* winma heenatigala <<a href="mailto:winma2014al@gmail.com" target="_blank">winma2014al@gmail.com</a>> [2018-08-29 05:57]:<br>
> To report this problem, please contact the site administrator at winma@test.<br>
[...]<br>
> No session initiator found with id (ECP), check requireSessionWith command.<br>
<br>
That seems pretty clear to me?<br>
<br>
> <Location /myservice/><br>
> AuthType shibboleth<br>
> ShibRequestSetting requireSessionWith ECP<br>
> Require valid-user<br>
> </Location><br>
<br>
For whatever reason (what documentation are you following here?)<br>
you're asking the the software to initiate a session with a named<br>
session initiator, here called "ECP". That name is arbitrary and up to<br>
you, and you don't seem to have such a session initiator defined.<br>
<br>
So why are you doing this in the first place?<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>