<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:10.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt">I'm a little confused by this line: "</span><span style="font-size:11.0pt">So I was able to navigate to the EntityID, got a CAC login, and successfully logged in".<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Are you protecting your IdP metadata endpoint? If so, that's likely the problem. It should allow anonymous access to the IdP metadata.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Your NetApp is likely trying to visit the metadata URL but isn't receiving XML, but receiving a 200/302 text/html response.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">- Steve</span><span style="font-size:11.0pt"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
</span></b><span style="font-size:12.0pt;color:black">users <users-bounces@shibboleth.net> on behalf of Matt Swann via users <users@shibboleth.net><br>
<b>Date: </b>Tuesday, October 11, 2022 at 7:38 AM<br>
<b>To: </b>Nate Klingenstein <ndk@signet.id><br>
<b>Cc: </b>Matt Swann <mswann090@gmail.com>, Shib Users <users@shibboleth.net><br>
<b>Subject: </b>Re: Error 404 when saving IdP Entity ID in NetApp<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">Thanks Nate. This was super helpful and guided me in the right direction. <o:p></o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">So I was able to navigate to the EntityID, got a CAC login, and successfully logged in. <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">I tried to tie the IdP entityID. to NetApp and received:<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">" Complete: SAML job failed, Reason: IdP metadata downloaded from the provided URL does not have the "entityID" attribute with namespace "urn:oasis:names:tc:SAML:2.0:metadata". <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">I'm going to start digging into that error more now. It's definitely headed in the right direction as NetApp can now download the Metadata from the IdP just I just need to fix this error now. <o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">Thanks again,<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">Matt <o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">On Fri, Oct 7, 2022 at 12:00 PM Nate Klingenstein <<a href="mailto:ndk@signet.id">ndk@signet.id</a>> wrote:<o:p></o:p></span></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal"><span style="font-size:11.0pt">Matt,<br>
<br>
> Is it possible this could be a port issue within the firewall given your experience?<br>
<br>
That depends on the firewall, but it's more likely to be a 404 from some other entity.  Have you checked to see whether it's the Servlet container returning the 404?  If so, that would indicate that it's not routing requests to the IdP correctly even if the
 IdP is apparently instantiating fine.  You might try querying <a href="https://urldefense.com/v3/__https:/localhost/idp/shibboleth__;!!IBzWLUs!XnAVMGSF9gnVdhay9GteQGL6CYrClTOYh0lOEQG6MJl9wKmT1ndWztn2QydGXGTD0xJhNnDMqCmKUEjf$" target="_blank">
https://localhost/idp/shibboleth</a> from the server itself.<br>
<br>
> Before I do that, is there anything else you might know that could cause this issue?<br>
<br>
All sorts of things in the web hosting environment could be implicated, and they're more probable root causes than a firewall.<br>
<br>
Take care,<br>
Nate<br>
<br>
--------<br>
Signet, Inc.<br>
The Art of Access ®<br>
<br>
<a href="https://urldefense.com/v3/__https:/www.signet.id__;!!IBzWLUs!XnAVMGSF9gnVdhay9GteQGL6CYrClTOYh0lOEQG6MJl9wKmT1ndWztn2QydGXGTD0xJhNnDMqJRtCnQ8$" target="_blank">https://www.signet.id</a><br>
<br>
-----Original message-----<br>
From: Matt Swann via users<br>
Sent: Friday, October 7 2022, 5:13 am<br>
To: Shib Users<br>
Cc: Matt Swann<br>
Subject: Re: Error 404 when saving IdP Entity ID in NetApp<br>
<br>
Hey Everyone,<br>
<br>
Thanks for all the help. I just wanted to provide an update. All of the errors are cleared in the logs and it's only info messages at this point. I unfortunately am still getting a 404 error when trying to navigate to the EntityID within a browser. Also, when
 I try to add the EntityID within NetApp I get an error saying it can't receive the IdP metadata.<br>
<br>
Is it possible this could be a port issue within the firewall given your experience? I'd have to submit a request to that specific team to make sure the correct ports are open. Before I do that, is there anything else you might know that could cause this issue?<br>
<br>
Thanks again!<br>
<br>
Matt<o:p></o:p></span></p>
</blockquote>
</div>
</div>
</body>
</html>