<div dir="ltr"><div class="gmail_default" style="font-size:small">So over the years I have successfully added quite a few SP to our IDP but this past week I have run into one that I am having trouble getting working.  I believe there is some mismatch with their metadata vs. what they are requesting.</div><div class="gmail_default" style="font-size:small"><br></div><div class="gmail_default" style="font-size:small">Here is the error log a user sees when trying to access the SP:<br></div><div style="margin-left:40px">Login - Unable to Respond<span class="gmail_default" style="font-size:small"></span><br></div><div style="margin-left:40px">The login service was unable to identify a compatible way to respond to the requested application. This is generally to due to a misconfiguration on the part of the application and should be reported to the application's support team or owner.</div><div><br></div><div><div style="font-size:small" class="gmail_default">On the IDP side ( 3.3.1 - I know, we need to upgrade to 4) , I see these errors:</div><div style="font-size:small" class="gmail_default"><span style="font-family:monospace">idp-process.log:2020-05-15 13:13:02,959 - DEBUG [org.opensaml.saml.common.binding.impl.DefaultEndpointResolver:126] - Endpoint Resolver org.opensaml.saml.common.binding.impl.DefaultEndpointResolver: Neither candidate endpoint location '<a href="https://saml-live.scenariolearning.com/saml/acs?dest=gustavus-mn.safecolleges.com">https://saml-live.scenariolearning.com/saml/acs?dest=gustavus-mn.safecolleges.com</a>' nor response location 'null' matched '<a href="https://saml-live.scenariolearning.com/saml/acs?dest=gustavus.mn.safecolleges.com">https://saml-live.scenariolearning.com/saml/acs?dest=gustavus.mn.safecolleges.com</a>'  (ipv6 ip address removed)<br></span></div><div style="font-size:small" class="gmail_default"><span style="font-family:monospace"><br></span></div><div style="font-size:small" class="gmail_default"><span style="font-family:monospace">idp-process.log:2020-05-15 13:13:02,959 - WARN [net.shibboleth.idp.saml.profile.impl.PopulateBindingAndEndpointContexts:410] - Profile Action PopulateBindingAndEndpointContexts: Unable to resolve outbound message endpoint for relying party '<a href="http://saml-live.scenariolearning.com">saml-live.scenariolearning.com</a>': EndpointCriterion [type={urn:oasis:names:tc:SAML:2.0:metadata}AssertionConsumerService, Binding=urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST, Location=<a href="https://saml-live.scenariolearning.com/saml/acs?dest=gustavus.mn.safecolleges.com">https://saml-live.scenariolearning.com/saml/acs?dest=gustavus.mn.safecolleges.com</a>, trusted=false] (ipv6 ip address removed)</span></div><div style="font-size:small" class="gmail_default"><br></div><div style="font-size:small" class="gmail_default">Am I correct that the error message says that the endpoint location does not match however they look identical?  Is there an issue with a question mark in there?  Hopefully I am just overlooking something obvious and you all can point it out for me :)<br></div><div style="font-size:small" class="gmail_default"><br></div><div style="font-size:small" class="gmail_default">The SP claims they have this working with other customers using Shibboleth.  Wondering if anyone has any idea what might be wrong on my end, or what I should tell the SP they need to fix? <br></div><br></div><div><div style="font-size:small" class="gmail_default">sadfasdf</div><br></div></div>