<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
<span style="font-size: 14px;" class="">Hi All,</span>
<div class=""><span style="font-size: 14px;" class=""><br class="">
</span></div>
<div class=""><span style="font-size: 14px;" class="">I recently stood up a v3.42 IDP.  I am testing by creating an entry in my /etc/hosts file for the new IDP hostname and IP address.  So far most of the SPs I visit can’t tell the difference since I am using
 the old v2 cert and key as the signing cert and key.  However I have a handful of SPs that are giving me the following error</span></div>
<div class="">
<p class="error" style="margin-top: 20px; margin-bottom: 20px; font-weight: bold; font-variant-ligatures: normal; orphans: 2; widows: 2;">
<span style="font-size: 14px;" class="">opensaml::FatalProfileException at (<a href="https://sp.fdu.edu/Shibboleth.sso/SAML2/POST" class="">https://sp.fdu.edu/Shibboleth.sso/SAML2/POST</a>)</span></p>
<p style="margin-top: 20px; margin-bottom: 20px; font-variant-ligatures: normal; orphans: 2; widows: 2;" class="">
<span style="font-size: 14px;" class="">Your client's current address (X.X.X.X) differs from the one used when you authenticated to your identity provider. To correct this problem, you may need to bypass a proxy server. Please contact your local support staff
 or help desk for assistance.</span></p>
<div class=""><span style="font-size: 14px;" class="">I know that I am solely hitting the new IDP based on updates to the login page. As well as I only have my wired connect turned on. On the SPs I see</span></div>
</div>
<div class=""><span style="font-size: 14px;" class=""><br class="">
</span></div>
<div class="">
<div class=""><span style="font-size: 14px;" class="">2019-02-01 16:04:09 DEBUG OpenSAML.MessageDecoder.SAML2 [198]: extracting issuer from SAML 2.0 protocol message</span></div>
<div class=""><span style="font-size: 14px;" class="">2019-02-01 16:04:09 DEBUG OpenSAML.MessageDecoder.SAML2 [198]: message from (<a href="https://idp.fdu.edu/idp/shibboleth" class="">https://idp.fdu.edu/idp/shibboleth</a>)</span></div>
<div class=""><span style="font-size: 14px;" class="">2019-02-01 16:04:09 DEBUG OpenSAML.MessageDecoder.SAML2 [198]: searching metadata for message issuer...</span></div>
<div class=""><span style="font-size: 14px;" class="">2019-02-01 16:04:09 WARN Shibboleth.SSO.SAML2 [198]: detected a problem with assertion: Your client's current address (<span style="orphans: 2; widows: 2;" class="">X.X.X.X</span>) differs from the one used
 when you authenticated to your identity provider. To correct this problem, you may need to bypass a proxy server. Please contact your local support staff or help desk for assistance.</span></div>
<div class=""><span style="font-size: 14px;" class=""><br class="">
</span></div>
</div>
<div class=""><span style="font-size: 14px;" class="">The problematic SPs are Shibboleth v2.5.X</span></div>
<div class=""><span style="font-size: 14px;" class=""><br class="">
</span></div>
<div class=""><span style="font-size: 14px;" class="">Has anyone had this problem during an upgrade?</span></div>
<div class=""><span style="font-size: 14px;" class=""><br class="">
</span></div>
<div class=""><span style="font-size: 14px;" class="">-Chris</span></div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
</body>
</html>