<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<div class="moz-cite-prefix">It says it loaded your metadata file,
but it doesn't say it loaded an EntityDescriptor with an id=<a class="moz-txt-link-rfc2396E" href="http://www.okta.com/exk137opma7Z4PsLC0x8">"http://www.okta.com/exk137opma7Z4PsLC0x8"</a>
(which is what you've set your Okta IdP entity ID in the proxy
settings in the shib IdP according to the logs) and an
SPSSODescriptor element.</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">Double check the Okta IdP metadata
file...<br>
</div>
<div class="moz-cite-prefix"><br>
</div>
<div class="moz-cite-prefix">On 2/23/2024 4:54 PM, Jewett, David via
users wrote:<br>
</div>
<blockquote type="cite"
cite="mid:SJ2PR16MB6301009D2A2A4B46188CCBDD95552@SJ2PR16MB6301.namprd16.prod.outlook.com">
<p class="MsoNormal">I’ve been tasked with implementing proxying
from our Shib IDP to Okta, to provide MFA for specific
Shibboleth SPs. I have a test IDP running 4.3.1, and I’ve
followed the SAMLAuthnConfiguration wiki docs for 4.0:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><a
href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1282539600/SAMLAuthnConfiguration"
moz-do-not-send="true" class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1282539600/SAMLAuthnConfiguration</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">and the “Using SAML Proxying to another IdP”
wiki article as well, with the understanding that some
configuration may be out of date for 4.1:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><a
href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1459979597/Using+SAML+Proxying+to+another+IdP"
moz-do-not-send="true" class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1459979597/Using+SAML+Proxying+to+another+IdP</a><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Per the above article, I created a
Shib-sp-metadata.xml file and included the following in
Metadata-providers.xml:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"> <MetadataProvider
id="ShibSPMetadata" xsi:type="FilesystemMetadataProvider"
metadataFile="%{idp.home}/metadata/sp-metadata.xml"/><o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
<p class="MsoNormal"> <MetadataProvider
id="OktaIDPMetadata" xsi:type="FilesystemMetadataProvider"
metadataFile="%{idp.home}/metadata/OktaIDPmetadata.xml"/><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">After configuration according to the
documentation, when accessing an SP authentication at the
upstream IDP succeeds, but my Shib IDP responds with “Web Login
Service – Unsupported request. The application you have accessed
is not registered for use with this service.”<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">My logs show that my upstream IDP’s metadata
is being loaded, as is the metadata for the Shib SP:</p>
</blockquote>
<p><br>
</p>
<pre class="moz-signature" cols="72">--
%% Christopher A. Bongaarts %% <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a> %%
%% OIT - Identity Management %% <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a> %%
%% University of Minnesota %% +1 (612) 625-1809 %%
</pre>
</body>
</html>