Skip to Content.
Sympa Menu

comanage-users - Re: [comanage-users] Trouble with the Comanage Release 2 VM

Subject: COmanage Users List

List archive

Re: [comanage-users] Trouble with the Comanage Release 2 VM

Chronological Thread 
  • From: Paul Caskey <>
  • To: Jeremy Rosenberg <>
  • Cc: "" <>
  • Subject: Re: [comanage-users] Trouble with the Comanage Release 2 VM
  • Date: Wed, 8 Feb 2017 21:14:31 +0000
  • Accept-language: en-US
  • Authentication-results:; dkim=none (message not signed) header.d=none;; dmarc=none action=none;
  • Ironport-phdr: 9a23:Y4+boh2FxSUsmU06smDT+DRfVm0co7zxezQtwd8ZseMfLvad9pjvdHbS+e9qxAeQG96Kt7QU0aGP7/6ocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbQhFgDWwbalxIRmoogndq8YbjIp/Iast1xXFpWdFdf5Lzm1yP1KTmBj85sa0/JF99ilbpuws+c1dX6jkZqo0VbNXAigoPGAz/83rqALMTRCT6XsGU2UZiQRHDg7Y5xznRJjxsy/6tu1g2CmGOMD9UL45VSi+46ptVRTlkzkMOSIn/27Li8xwlKNbrwynpxxj2I7ffYWZOONjcq/BYd8WQGxMVdtTWSNcGIOxd4sBAfQcM+ZEoYfzpFUOohm/BQawC+zi0SVHimPz3aAgz+gtDQPL0Qo9FNwOqnTUq9D1Ob8IX++v0anIySjIYu1M1jfm64jHbBAgquyLULJobcXe01IvFwDbgVSQsoHlPjWV1vgTvGiB6epvS/6vh3A9pw5vvzev294hh4/UjYwbzVDE8D92wIczJdCgSU57Z8KkH4VKtyGcKYR2Xt0uT3t2tykn170KoYO3cSkOxZg92RLTdfiKf5KW7h7/UOudOzR1iXNjdbmihBiy6VCtxvPhWsS1ylpHoDRJnsPRun0OyxDf8NWLR/ll8ku/xTqDyx3f5+RLLE03j6XWKJssz78zm5odr0vOGyH2mEv4jKCIc0gp+Oul5uvkb7jjuJORNIF0hh/7P6gzgMOyBeA1Pw0SUGWV+umzyLvu9lDjTrpQlP05iKzZvYjaJcsFoq65BBdY3J4/5hi4Ezuqzs0Uk2QfIl5YYR6HiJPmNE/ULPD/EPe/n0+jkDB2x/DAI7LtGI3NLmLEkLf9Y7ly91JcyAs0zdBZ/Z5UDawBIO73Wk/2s9zYDQU1PBCzw+biENl914UeVnyTAqKBLq/erF6F6vghLuWSfoMZpTXwJ+Q/6/Lzj3I1gVodcrOo3ZsTZnC4BPNmI0CBbHr0ntgOC3wKvgkgQ+3qk1CCUDhTZ2qsUKIm4DE0Fp6mAZnZSo+znbOBwT+3HodKaWBeFlCMDXDoep2YVPcLbSKdOMlhnSYLVbe/UoMhyAquuxHgy7p8NefU/iwYtYn/1Nhu+eHfjxAy9TpoD8uDyWGNSX97nn8WSzMswq9wvFF9mR+/1v1ajuZVEM0b3fRSXwEwOITTh7hgDMv/SyrLc82KRVKrU5OrDSxnHfwrxNpbW09gH52JhwvA0jviV6cenqeICY0c86TA0mL3KtonjXvKyf9y3BEdXsJTODj+1eZE/A/JCtuMyh3Bmg==
  • Spamdiagnosticoutput: 1:0

Thanks for letting me know, Jeremy.


Feedback to the TIER program will be much appreciated.  COmanage is a powerful platform that we are eager to see deployed across the community.




From: Jeremy Rosenberg <>
Date: Wednesday, February 8, 2017 at 2:51 PM
To: Paul Caskey <>
Cc: "" <>
Subject: Re: [comanage-users] Trouble with the Comanage Release 2 VM


Thanks Paul


It’s working great now I was able to get the VM running.


Looks good.





Jeremy Rosenberg

Manager, CalNet Identity and Access Management 

UC Berkeley





On Feb 7, 2017, at 8:29 PM, Paul Caskey <> wrote:


Hi Jeremy-

As you’ve diagnosed, this looks to be a shibb SP metadata problem.

The error at the IdP was:
2017-02-08 00:19:50,293 - INFO [org.opensaml.saml.common.binding.impl.SAMLMetadataLookupHandler:128] - Message Handler:  No metadata returned for in role {urn:oasis:names:tc:SAML:2.0:metadata}SPSSODescriptor with protocol urn:oasis:names:tc:SAML:2.0:protocol

I see metadata for the entityID above, but the IDP is not reloading it every 5 minutes as it was told to do.

This IdP is an atypical install and it’s not doing well at the moment and I’m having trouble figuring it out (how many tomcat instances does one server need?), so it may be flaky for a little bit tonight…


On 2/7/17, 6:46 PM, " on behalf of Jeremy Rosenberg" < on behalf of > wrote:

   I’m not sure if this is the place to seek support but I’m trying to test out COmanage Registry R2 V2.

   I followed all the steps at:

   And the VM is running.  I can bring up the UI at https://[IP Address]/registry

   I click the Login button.

   I select TIER Testbed Shibboleth IdP which has this link:

   https://[IP Address]/Shibboleth.sso/Login?SAMLDS=1&target=ss%3Amem%3A327c412aa271be0ba1a80657242073f24c0bb2b06520c4c80a97cdb2d0410819&

   Which brings up an error page on

   “Web Login Service - Unsupported Request”
   “The application you have accessed is not registered for use with this service”

   This is after waiting for a long time after registering my SPs, on several different days.

   I assume I have made a mistake when registering my VM as an SP in the testbed IDP.  But I’m not sure how to debug that.

   If there is somewhere else I need to go for support on adding my VM as an SP to the testbed, please let me know.


   P.S. As an aside, someone should clean up the "Configuring the COmanage Release" page.  It looks like some bullets were added, but the references to earlier steps within the text was not updated.  So now references are confusing. For example, Step 2.r. references the certificate output in 2.o.  But the certificate output is now described in 2.q.  (I kept thinking I missed somekind of output from script)

   Jeremy Rosenberg
   Manager, CalNet Identity and Access Management
   UC Berkeley


Archive powered by MHonArc 2.6.19.

Top of Page