<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Based on your message, you've configured AWS to redirect to Google to start the SSO flow instead of your IdP. There's your problem. You'll need to point AWS Cognito at your Identity Provider in order to actually test it.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
It's been a while since I configured our Cognito integration, but for any given SP, you typically either can upload your Identity Provider's metadata, or manually have to specify one of your SingleSignOnService endpoints to use, along with the other particulars
of your environment.<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Em<br>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of leosimon <leosimon@digital-nirvana.com><br>
<b>Sent:</b> Friday, April 24, 2020 11:05 AM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> [External] ShibV4-LdapCognito Issue</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">I have configured Shibboleth V4 with LDAP Auth for SP AWS Cognito. For<br>
testing, call back urls are given as <a href="https://google.com">https://google.com</a>. I can see from<br>
idp-process.log and confirm that service running fine and metadata pulled<br>
from remote but when I visit the SP URL and click on login, it just returns<br>
with the URL as and no logs captured in the server.<br>
<br>
<a href="https://www.google.com/?error=server_error">https://www.google.com/?error=server_error</a><br>
<br>
At the same time, I can get the results from cli using this,<br>
<br>
bin/aacli.sh --url <a href="https://idp.example.com/idp">https://idp.example.com/idp</a> --requester<br>
urn:amazon:cognito:sp:exmapleURNofSP --principal leosimon<br>
--changed the url as example.<br>
<br>
I am completely blank and unable to proceed further, Can someone help me<br>
where the error would me and what I might missed? <br>
<br>
<br>
<br>
--<br>
Sent from: <a href="https://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">
https://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>