<div dir="ltr"><div class="gmail_default" style="font-family:tahoma,sans-serif"><div class="gmail_default" style="font-family:tahoma,sans-serif">I have successfully tested my Shibboleth set up against SAML test: <a href="https://samltest.id/" target="_blank">https://samltest.id/</a></div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif">Now I wish to connect to the server described at:</div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif"><a href="https://idp-dev.nss.udel.edu/idp/shibboleth" target="_blank">https://idp-dev.nss.udel.edu/idp/shibboleth</a></div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default" style="font-family:tahoma,sans-serif">I set up the SSO description in shibboleth2.xml as:</div><div class="gmail_default" style="font-family:tahoma,sans-serif"><br></div><div class="gmail_default"><span style="font-family:monospace"><<b>SSO</b> entityID="<a href="https://idp-dev.nss.udel.edu/idp/shibboleth" target="_blank">https://idp-dev.nss.udel.edu/idp/shibboleth</a>" discoveryProtocol="SAMLDS" discoveryURL="<a href="https://idp-dev.nss.udel.edu/idp/profile/Shibboleth/SSO" target="_blank">https://idp-dev.nss.udel.edu/idp/profile/Shibboleth/SSO</a>"><br> SAML2<br></SSO></span></div><div class="gmail_default"><span style="font-family:monospace"><br></span></div><div class="gmail_default"><span style="font-family:verdana,sans-serif">Now I get:<br></span></div><div class="gmail_default" style="font-family:tahoma,sans-serif"><h1>Unknown or Unusable Identity Provider</h1>
<p>The identity provider supplying your login credentials is not authorized
for use with this service or does not support the necessary capabilities.</p>
<p>To report this problem, please contact the site administrator at
<a href="mailto:root@localhost" target="_blank">root@localhost</a>.
</p>
<p>Please include the following error message in any email:</p>
<p>Identity provider lookup failed at (<a href="http://www.appaapps.com/" target="_blank">http://www.appaapps.com/</a>)</p>
<p><strong>EntityID:</strong> <a href="https://idp-dev.nss.udel.edu/idp/shibboleth" target="_blank">https://idp-dev.nss.udel.edu/idp/shibboleth</a></p>
<p>opensaml::saml2md::MetadataException: Unable to locate metadata for
identity provider (<a href="https://idp-dev.nss.udel.edu/idp/shibboleth" target="_blank">https://idp-dev.nss.udel.edu/idp/shibboleth</a>)</p></div><div><br></div><div><div style="font-family:tahoma,sans-serif" class="gmail_default">Please tell me how to set up the <b>SSO</b> tag to reach this server? </div></div><font color="#888888"><div><br><br></div></font></div><br>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><span style="font-family:tahoma,sans-serif">Thanks,<br><br></span><div dir="ltr"><span style="font-family:tahoma,sans-serif"><a href="https://metacpan.org/author/PRBRENAN" target="_blank">Phil</a><br><br></span><div><a href="https://metacpan.org/author/PRBRENAN" target="_blank"><span style="font-family:tahoma,sans-serif">Philip R Brenan</span></a></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div>