Metadata question for Embedded Discovery and SP authentication of IdP

Tom Scavo trscavo at gmail.com
Tue Aug 2 23:46:53 BST 2011


On Tue, Aug 2, 2011 at 6:41 PM, Tom Scavo <trscavo at gmail.com> wrote:
> On Tue, Aug 2, 2011 at 4:47 PM, Jason Bau <jasonbau at gmail.com> wrote:
>>
>> Here's my question:  is the expired cert to blame for my SP failing to
>> authenticate the IdP?
>
> No, I'm pretty sure that's not it.

Are you sure the SP's metadata has one or more SAML V2.0
<md:AsssertionConsumerService> endpoints? Maybe your SP has been
issuing SAML1 requests all along and you didn't realize that. Now it's
issuing SAML2 requests without proper support in metadata. See the
InCommon wiki (https://spaces.internet2.edu/x/FgEFAQ) for details.

Tom


More information about the users mailing list