<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <div class="moz-cite-prefix">It says it loaded your metadata file,
      but it doesn't say it loaded an EntityDescriptor with an id=<a class="moz-txt-link-rfc2396E" href="http://www.okta.com/exk137opma7Z4PsLC0x8">"http://www.okta.com/exk137opma7Z4PsLC0x8"</a>
      (which is what you've set your Okta IdP entity ID in the proxy
      settings in the shib IdP according to the logs) and an
      SPSSODescriptor element.</div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">Double check the Okta IdP metadata
      file...<br>
    </div>
    <div class="moz-cite-prefix"><br>
    </div>
    <div class="moz-cite-prefix">On 2/23/2024 4:54 PM, Jewett, David via
      users wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:SJ2PR16MB6301009D2A2A4B46188CCBDD95552@SJ2PR16MB6301.namprd16.prod.outlook.com">
      <p class="MsoNormal">I’ve been tasked with implementing proxying
        from our Shib IDP to Okta, to provide MFA for specific
        Shibboleth SPs. I have a test IDP running 4.3.1, and I’ve
        followed the SAMLAuthnConfiguration wiki docs for 4.0:<o:p></o:p></p>
      <p class="MsoNormal"><o:p> </o:p></p>
      <p class="MsoNormal"><a
href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1282539600/SAMLAuthnConfiguration"
          moz-do-not-send="true" class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1282539600/SAMLAuthnConfiguration</a><o:p></o:p></p>
      <p class="MsoNormal"><o:p> </o:p></p>
      <p class="MsoNormal">and the “Using SAML Proxying to another IdP”
        wiki article as well, with the understanding that some
        configuration may be out of date for 4.1:<o:p></o:p></p>
      <p class="MsoNormal"><o:p> </o:p></p>
      <p class="MsoNormal"><a
href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1459979597/Using+SAML+Proxying+to+another+IdP"
          moz-do-not-send="true" class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1459979597/Using+SAML+Proxying+to+another+IdP</a><o:p></o:p></p>
      <p class="MsoNormal"><o:p> </o:p></p>
      <p class="MsoNormal">Per the above article, I created a
        Shib-sp-metadata.xml file and included the following in
        Metadata-providers.xml:<o:p></o:p></p>
      <p class="MsoNormal"><o:p> </o:p></p>
      <p class="MsoNormal">                <MetadataProvider
        id="ShibSPMetadata"  xsi:type="FilesystemMetadataProvider"
        metadataFile="%{idp.home}/metadata/sp-metadata.xml"/><o:p></o:p></p>
      <p class="MsoNormal">                                <o:p></o:p></p>
      <p class="MsoNormal">                <MetadataProvider
        id="OktaIDPMetadata"  xsi:type="FilesystemMetadataProvider"
        metadataFile="%{idp.home}/metadata/OktaIDPmetadata.xml"/><o:p></o:p></p>
      <p class="MsoNormal"><o:p> </o:p></p>
      <p class="MsoNormal">After configuration according to the
        documentation, when accessing an SP authentication at the
        upstream IDP succeeds, but my Shib IDP responds with “Web Login
        Service – Unsupported request. The application you have accessed
        is not registered for use with this service.”<o:p></o:p></p>
      <p class="MsoNormal"><o:p> </o:p></p>
      <p class="MsoNormal">My logs show that my upstream IDP’s metadata
        is being loaded, as is the metadata for the Shib SP:</p>
    </blockquote>
    <p><br>
    </p>
    <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a>          %%
%%  OIT - Identity Management  %%  <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a>  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
</pre>
  </body>
</html>