<div dir="ltr"><div>Fazla,</div><div><br></div><div>If ShibCas is enabled, then it would be redirecting you to the ShibCas endpoint next, but your IdP is getting stuck 1 step earlier in the process. It won't accept an AuthnRequest message intended for a different location than the one that Shibboleth is running at. This is a security check in SAML.</div><div><br></div><div>You need to use your real address or configure your web server so that it believes that its name is always <a href="http://idp.myuni.edu">idp.myuni.edu</a>, no matter what your browser uses. That will override the location used by the client and the message will match the location anyway.</div><div><br></div><div>Take care,</div><div>Nate.<br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Sep 13, 2018 at 6:32 AM, fazla <span dir="ltr"><<a href="mailto:fazlarabby043264@gmail.com" target="_blank">fazlarabby043264@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Nate,<br>
<br>
Thank you once again for your detail reply. <br>
<br>
I have added the meta provider for the samltest. So when I provide my<br>
entityId for testing after uploading my idp-metadata.xml<br>
<br>
it redirects me to<br>
<a href="https://idp.myuni.edu/idp/profile/SAML2/Redirect/SSO?SAMLRequest=fZJRT4MwFIX%2FCun7KIUZt2aQ4PbgkunIQB98MR3cSZPSYm9R9%2B%2BFMeNMzN6a9pzv5Jx0gaJRLU87V%2BsdvHeAzvtqlEZ%2BeohJZzU3AiVyLRpA7kqepw8bHvoBb61xpjSKeCkiWCeNXhqNXQM2B%2FshS3jabWJSO9cip3Qguj7AlxXNa7nfGwWu9hENHZAhzbZ5QbxVL5FaDLRfr6xaX7RSOh%2Bqzm%2BOwwXt8w9Swdm9g0paKB3N8y3x1quYvEZTJqJZJGYhY%2Bx2HlXhlEWsDAQDmB%2FCeS9D7GCt0QntYhIGbDYJ5hMWFUHEbxgPghfiZeead1JXUr9d32Q%2FipDfF0U2GRs9g8VTm15AksWwAz8F24utr2PFz8Ak%2BW%2FO4UyxXdAL9hjU8scetl5lRsny6KVKmc%2BlBeEgJozQZLT8%2FQHJNw%3D%3D&RelayState=ss%3Amem%3A0fc4bb139d00808ae2fd3396bfd47333891be875fcde4bb77d65f07d8276ad88" rel="noreferrer" target="_blank">https://idp.myuni.edu/idp/<wbr>profile/SAML2/Redirect/SSO?<wbr>SAMLRequest=fZJRT4MwFIX%<wbr>2FCun7KIUZt2aQ4PbgkunIQB98MR3c<wbr>SZPSYm9R9%2B%<wbr>2BFMeNMzN6a9pzv5Jx0gaJRLU87V%<wbr>2BsdvHeAzvtqlEZ%<wbr>2BeohJZzU3AiVyLRpA7kqepw8bHvoB<wbr>b61xpjSKeCkiWCeNXhqNXQM2B%<wbr>2FshS3jabWJSO9cip3Qguj7AlxXNa7<wbr>nfGwWu9hENHZAhzbZ5QbxVL5FaDLRf<wbr>r6xaX7RSOh%2Bqzm%<wbr>2BOwwXt8w9Swdm9g0paKB3N8y3x1qu<wbr>YvEZTJqJZJGYhY%<wbr>2Bx2HlXhlEWsDAQDmB%<wbr>2FCeS9D7GCt0QntYhIGbDYJ5hMWFUH<wbr>EbxgPghfiZeead1JXUr9d32Q%<wbr>2FipDfF0U2GRs9g8VTm15AksWwAz8F<wbr>24utr2PFz8Ak%2BW%<wbr>2FO4UyxXdAL9hjU8scetl5lRsny6KV<wbr>Kmc%2BlBeEgJozQZLT8%2FQHJNw%<wbr>3D%3D&RelayState=ss%3Amem%<wbr>3A0fc4bb139d00808ae2fd3396bfd4<wbr>7333891be875fcde4bb77d65f07d82<wbr>76ad88</a><br>
<br>
<br>
Of cource this will give me an error as I don't have the server yet but when<br>
I change this to <br>
<br>
<a href="https://localhost:8443/idp/profile/SAML2/Redirect/SSO?SAMLRequest=fZJRT4MwFIX%2FCun7KIUZt2aQ4PbgkunIQB98MR3cSZPSYm9R9%2B%2BFMeNMzN6a9pzv5Jx0gaJRLU87V%2BsdvHeAzvtqlEZ%2BeohJZzU3AiVyLRpA7kqepw8bHvoBb61xpjSKeCkiWCeNXhqNXQM2B%2FshS3jabWJSO9cip3Qguj7AlxXNa7nfGwWu9hENHZAhzbZ5QbxVL5FaDLRfr6xaX7RSOh%2Bqzm%2BOwwXt8w9Swdm9g0paKB3N8y3x1quYvEZTJqJZJGYhY%2Bx2HlXhlEWsDAQDmB%2FCeS9D7GCt0QntYhIGbDYJ5hMWFUHEbxgPghfiZeead1JXUr9d32Q%2FipDfF0U2GRs9g8VTm15AksWwAz8F24utr2PFz8Ak%2BW%2FO4UyxXdAL9hjU8scetl5lRsny6KVKmc%2BlBeEgJozQZLT8%2FQHJNw%3D%3D&RelayState=ss%3Amem%3A0fc4bb139d00808ae2fd3396bfd47333891be875fcde4bb77d65f07d8276ad88" rel="noreferrer" target="_blank">https://localhost:8443/idp/<wbr>profile/SAML2/Redirect/SSO?<wbr>SAMLRequest=fZJRT4MwFIX%<wbr>2FCun7KIUZt2aQ4PbgkunIQB98MR3c<wbr>SZPSYm9R9%2B%<wbr>2BFMeNMzN6a9pzv5Jx0gaJRLU87V%<wbr>2BsdvHeAzvtqlEZ%<wbr>2BeohJZzU3AiVyLRpA7kqepw8bHvoB<wbr>b61xpjSKeCkiWCeNXhqNXQM2B%<wbr>2FshS3jabWJSO9cip3Qguj7AlxXNa7<wbr>nfGwWu9hENHZAhzbZ5QbxVL5FaDLRf<wbr>r6xaX7RSOh%2Bqzm%<wbr>2BOwwXt8w9Swdm9g0paKB3N8y3x1qu<wbr>YvEZTJqJZJGYhY%<wbr>2Bx2HlXhlEWsDAQDmB%<wbr>2FCeS9D7GCt0QntYhIGbDYJ5hMWFUH<wbr>EbxgPghfiZeead1JXUr9d32Q%<wbr>2FipDfF0U2GRs9g8VTm15AksWwAz8F<wbr>24utr2PFz8Ak%2BW%<wbr>2FO4UyxXdAL9hjU8scetl5lRsny6KV<wbr>Kmc%2BlBeEgJozQZLT8%2FQHJNw%<wbr>3D%3D&RelayState=ss%3Amem%<wbr>3A0fc4bb139d00808ae2fd3396bfd4<wbr>7333891be875fcde4bb77d65f07d82<wbr>76ad88</a><br>
<br>
<br>
I see this in the browser <br>
<br>
<br>
Replace or remove this logo<br>
Web Login Service - Message Security Error<br>
The request cannot be fulfilled because the message received does not meet<br>
the security requirements of the login service.<br>
<br>
<br>
and the server log is <br>
<br>
[org.opensaml.saml.common.<wbr>binding.security.impl.<wbr>ReceivedEndpointSecurityHandle<wbr>r:200]<br>
- Message Handler: SAML message intended destination endpoint<br>
'<a href="https://idp.myuni.edu/idp/profile/SAML2/Redirect/SSO" rel="noreferrer" target="_blank">https://idp.myuni.edu/idp/<wbr>profile/SAML2/Redirect/SSO</a>' did not match the<br>
recipient endpoint '<a href="https://localhost:8443/idp/profile/SAML2/Redirect/SSO" rel="noreferrer" target="_blank">https://localhost:8443/idp/<wbr>profile/SAML2/Redirect/SSO</a>'<br>
<br>
Does that anything to do with the following idp.properties which is<br>
commented out by default.<br>
<br>
# Profile flows in which the ProfileRequestContext should be exposed<br>
# in servlet request under the key "<wbr>opensamlProfileRequestContext"<br>
#idp.profile.<wbr>exposeProfileRequestContextInS<wbr>ervletRequest =<br>
SAML2/POST/SSO,SAML2/Redirect/<wbr>SSO<br>
<br>
<br>
It's not supposed to redirect me to the cas client? I am allowing localhost<br>
in the CAS service registry <br>
<br>
This is the detail server log:<br>
<br>
Refreshing ApplicationContext:shibboleth.<wbr>MetadataResolverService: startup<br>
date [Thu Sep 13 03:50:44 UTC 2018]; parent: Root WebApplicationContext<br>
2018-09-13 03:50:47,202 - INFO<br>
<span class="">[org.opensaml.saml.metadata.<wbr>resolver.impl.<wbr>AbstractReloadingMetadataResol<wbr>ver:504]<br>
- Metadata Resolver FileBackedHTTPMetadataResolver SAMLtest: New metadata<br>
successfully loaded for '<a href="https://samltest.id/saml/sp" rel="noreferrer" target="_blank">https://samltest.id/saml/sp</a>'<br>
</span>2018-09-13 03:50:47,203 - INFO<br>
<span class="">[org.opensaml.saml.metadata.<wbr>resolver.impl.<wbr>AbstractReloadingMetadataResol<wbr>ver:324]<br>
- Metadata Resolver FileBackedHTTPMetadataResolver SAMLtest: Next refresh<br>
cycle for metadata provider '<a href="https://samltest.id/saml/sp" rel="noreferrer" target="_blank">https://samltest.id/saml/sp</a>' will occur on<br>
</span>'2018-09-13T06:50:45.950Z' ('2018-09-13T06:50:45.950Z' local time)<br>
2018-09-13 03:50:47,215 - INFO<br>
<span class="">[net.shibboleth.ext.spring.<wbr>service.<wbr>ReloadableSpringService:380] - Service<br>
'shibboleth.<wbr>MetadataResolverService': Completed reload and swapped in latest<br>
configuration for service 'shibboleth.<wbr>MetadataResolverService'<br>
</span>2018-09-13 03:50:47,215 - INFO<br>
<span class="">[net.shibboleth.ext.spring.<wbr>service.<wbr>ReloadableSpringService:387] - Service<br>
'shibboleth.<wbr>MetadataResolverService': Reload complete<br>
</span>2018-09-13 03:50:47,632 - INFO<br>
[net.shibboleth.ext.spring.<wbr>service.<wbr>ReloadableSpringService:380] - Service<br>
'shibboleth.<wbr>RelyingPartyResolverService': Completed reload and swapped in<br>
latest configuration for service 'shibboleth.<wbr>RelyingPartyResolverService'<br>
2018-09-13 03:50:47,632 - INFO<br>
[net.shibboleth.ext.spring.<wbr>service.<wbr>ReloadableSpringService:387] - Service<br>
'shibboleth.<wbr>RelyingPartyResolverService': Reload complete<br>
2018-09-13 03:50:47,633 - INFO<br>
[net.shibboleth.utilities.<wbr>java.support.service.<wbr>AbstractReloadableService:199]<br>
- Service 'shibboleth.<wbr>RelyingPartyResolverService': Reload time set to:<br>
900000, starting refresh thread<br>
2018-09-13 03:50:47,684 - INFO<br>
[net.shibboleth.utilities.<wbr>java.support.service.<wbr>AbstractReloadableService:172]<br>
- Service 'shibboleth.<wbr>ReloadableAccessControlService<wbr>': Performing initial<br>
load<br>
2018-09-13 03:50:47,684 - INFO<br>
[net.shibboleth.utilities.<wbr>java.support.service.<wbr>AbstractReloadableService:258]<br>
- Service 'shibboleth.<wbr>ReloadableAccessControlService<wbr>': Reloading service<br>
configuration<br>
2018-09-13 03:50:47,686 - INFO<br>
[net.shibboleth.ext.spring.<wbr>util.<wbr>SchemaTypeAwareXMLBeanDefiniti<wbr>onReader:317]<br>
- Loading XML bean definitions from file [C:\Program Files<br>
(x86)\Shibboleth\IdP\conf\<wbr>access-control.xml]<br>
2018-09-13 03:50:47,705 - INFO<br>
[net.shibboleth.ext.spring.<wbr>util.<wbr>SchemaTypeAwareXMLBeanDefiniti<wbr>onReader:317]<br>
- Loading XML bean definitions from file [C:\Program Files<br>
(x86)\Shibboleth\IdP\system\<wbr>conf\access-control-system.<wbr>xml]<br>
2018-09-13 03:50:47,861 - INFO<br>
[net.shibboleth.ext.spring.<wbr>context.<wbr>FilesystemGenericApplicationCo<wbr>ntext:583]<br>
- Refreshing ApplicationContext:shibboleth.<wbr>ReloadableAccessControlService<wbr>:<br>
startup date [Thu Sep 13 03:50:47 UTC 2018]; parent: Root<br>
WebApplicationContext<br>
2018-09-13 03:50:48,080 - INFO<br>
[net.shibboleth.ext.spring.<wbr>service.<wbr>ReloadableSpringService:380] - Service<br>
'shibboleth.<wbr>ReloadableAccessControlService<wbr>': Completed reload and swapped in<br>
latest configuration for service 'shibboleth.<wbr>ReloadableAccessControlService<wbr>'<br>
2018-09-13 03:50:48,080 - INFO<br>
[net.shibboleth.ext.spring.<wbr>service.<wbr>ReloadableSpringService:387] - Service<br>
'shibboleth.<wbr>ReloadableAccessControlService<wbr>': Reload complete<br>
2018-09-13 03:50:48,080 - INFO<br>
[net.shibboleth.utilities.<wbr>java.support.service.<wbr>AbstractReloadableService:199]<br>
- Service 'shibboleth.<wbr>ReloadableAccessControlService<wbr>': Reload time set to:<br>
300000, starting refresh thread<br>
2018-09-13 03:50:48,095 - INFO<br>
[net.shibboleth.utilities.<wbr>java.support.service.<wbr>AbstractReloadableService:172]<br>
- Service 'shibboleth.<wbr>ReloadableCASServiceRegistry': Performing initial load<br>
2018-09-13 03:50:48,095 - INFO<br>
[net.shibboleth.utilities.<wbr>java.support.service.<wbr>AbstractReloadableService:258]<br>
- Service 'shibboleth.<wbr>ReloadableCASServiceRegistry': Reloading service<br>
configuration<br>
2018-09-13 03:50:48,095 - INFO<br>
[net.shibboleth.ext.spring.<wbr>util.<wbr>SchemaTypeAwareXMLBeanDefiniti<wbr>onReader:317]<br>
- Loading XML bean definitions from file [C:\Program Files<br>
(x86)\Shibboleth\IdP\conf\cas-<wbr>protocol.xml]<br>
2018-09-13 03:50:48,314 - INFO<br>
[net.shibboleth.ext.spring.<wbr>context.<wbr>FilesystemGenericApplicationCo<wbr>ntext:583]<br>
- Refreshing ApplicationContext:shibboleth.<wbr>ReloadableCASServiceRegistry:<br>
startup date [Thu Sep 13 03:50:48 UTC 2018]; parent: Root<br>
WebApplicationContext<br>
2018-09-13 03:50:48,408 - INFO<br>
[net.shibboleth.ext.spring.<wbr>service.<wbr>ReloadableSpringService:380] - Service<br>
'shibboleth.<wbr>ReloadableCASServiceRegistry': Completed reload and swapped in<br>
latest configuration for service 'shibboleth.<wbr>ReloadableCASServiceRegistry'<br>
2018-09-13 03:50:48,408 - INFO<br>
[net.shibboleth.ext.spring.<wbr>service.<wbr>ReloadableSpringService:387] - Service<br>
'shibboleth.<wbr>ReloadableCASServiceRegistry': Reload complete<br>
2018-09-13 03:50:48,408 - INFO<br>
[net.shibboleth.utilities.<wbr>java.support.service.<wbr>AbstractReloadableService:199]<br>
- Service 'shibboleth.<wbr>ReloadableCASServiceRegistry': Reload time set to:<br>
900000, starting refresh thread<br>
2018-09-13 03:50:49,627 - INFO<br>
[net.shibboleth.ext.spring.<wbr>context.<wbr>DelimiterAwareApplicationConte<wbr>xt:583] -<br>
Refreshing WebApplicationContext for namespace 'idp-servlet': startup date<br>
[Thu Sep 13 03:50:49 UTC 2018]; parent: Root WebApplicationContext<br>
2018-09-13 03:50:51,330 - INFO<br>
[net.shibboleth.idp.authn.<wbr>impl.RemoteUserAuthServlet:<wbr>193] -<br>
RemoteUserAuthServlet will process REMOTE_USER, along with attributes [] and<br>
headers []<br>
2018-09-13 03:51:37,455 - ERROR<br>
[org.opensaml.saml.common.<wbr>binding.security.impl.<wbr>ReceivedEndpointSecurityHandle<wbr>r:200]<br>
- Message Handler: SAML message intended destination endpoint<br>
'<a href="https://idp.myuni.edu/idp/profile/SAML2/Redirect/SSO" rel="noreferrer" target="_blank">https://idp.myuni.edu/idp/<wbr>profile/SAML2/Redirect/SSO</a>' did not match the<br>
recipient endpoint '<a href="https://localhost:8443/idp/profile/SAML2/Redirect/SSO" rel="noreferrer" target="_blank">https://localhost:8443/idp/<wbr>profile/SAML2/Redirect/SSO</a>'<br>
2018-09-13 03:51:37,673 - WARN<br>
[net.shibboleth.idp.profile.<wbr>impl.<wbr>WebFlowMessageHandlerAdaptor:<wbr>202] - Profile<br>
Action WebFlowMessageHandlerAdaptor: Exception handling message<br>
org.opensaml.messaging.<wbr>handler.<wbr>MessageHandlerException: SAML message failed<br>
received endpoint check<br>
at<br>
org.opensaml.saml.common.<wbr>binding.security.impl.<wbr>ReceivedEndpointSecurityHandle<wbr>r.checkEndpointURI(<wbr>ReceivedEndpointSecurityHandle<wbr>r.java:202)<br>
2018-09-13 03:51:37,689 - WARN<br>
<span class="">[org.opensaml.profile.action.<wbr>impl.LogEvent:105] - A non-proceed event<br>
</span>occurred while processing the request: MessageAuthenticationError<br>
<div class="HOEnZb"><div class="h5"><br>
<br>
<br>
<br>
--<br>
Sent from: <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html" rel="noreferrer" target="_blank">http://shibboleth.1660669.n2.<wbr>nabble.com/Shibboleth-Users-<wbr>f1660767.html</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>