<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
</head>
<body bgcolor="#FFFFFF" text="#000000">
This is probably not a preferred solution, but I've been tasked to
determine if it is technically possible.<br>
And, yes, we did dig ourselves into this hole and are working on a
plan to get out, but other timelines do not want to wait...<br>
<br>
Here's the scenario:<br>
<ol>
<li>We currently have IDPv3 running behind an OLD hardware load
balancer with SSL offloading. </li>
<li>This old load balancer does not support newer ciphers,
including those with Perfect Forward Secrecy.</li>
<li>Apple is requiring PFS on OSX and iOS applications.</li>
<li>New SP added for an application that has a desktop client with
an embedded browser that requires PFS.</li>
<li>Expectation has been set that the new application be available
after winter break.<br>
</li>
</ol>
So, among others, a short term solution has been proposed to bring
up a very light weight virtual load balancer that supports the newer
ciphers. This virtual load balancer would not be able to handle all
of our IDP traffic, but can handle the traffic for this one SP. The
OLD load balancer endpoint is idp.calpoly.edu..., the virtual load
balancer would have an endpoint of idp.calpoly.org..., everything
else being the same.<br>
<br>
The error we see in the logs is:<br>
<blockquote><tt>2018-11-26 08:34:39,496 - ERROR
[org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:200]
- Message Handler: SAML message intended destination endpoint
'<a class="moz-txt-link-freetext" href="https://idp.calpoly.org/idp/profile/SAML2/Redirect/SSO">https://idp.calpoly.org/idp/profile/SAML2/Redirect/SSO</a>' did not
match the recipient endpoint
'<a class="moz-txt-link-freetext" href="https://idp.calpoly.edu/idp/profile/SAML2/Redirect/SSO">https://idp.calpoly.edu/idp/profile/SAML2/Redirect/SSO</a>'</tt><tt><br>
</tt><tt>2018-11-26 08:34:39,498 - WARN
[net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:202]
- Profile Action WebFlowMessageHandlerAdaptor: Exception
handling message</tt><tt><br>
</tt><tt>org.opensaml.messaging.handler.MessageHandlerException:
SAML message failed received endpoint check</tt><tt><br>
</tt><tt> at
org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler.checkEndpointURI(ReceivedEndpointSecurityHandler.java:202)</tt><br>
</blockquote>
So, here is the question:<br>
<br>
On the IDP, is it possible to configure a second recipient endpoint
that has a different domain name, allowing the IDP to pass the check
causing the error above?<br>
<br>
Thanks,<br>
Dan<br>
<br>
<br>
<br>
<br>
<br>
<br>
<br>
<div class="moz-signature">-- <br>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
<title></title>
Dan Malone<br>
<font color="#999999">Lead Identity Management Architect<br>
Information Technology Services<br>
California Polytechnic State University<br>
San Luis Obispo, California<br>
<br>
Direct 805-756-6326<br>
<a class="moz-txt-link-abbreviated" href="mailto:dmalone@calpoly.edu">dmalone@calpoly.edu</a></font><br>
</div>
</body>
</html>