SAML2 Request - "Destination" XML attribute.

Friedrich Clausen fred at derf.nl
Fri Aug 10 06:05:48 EDT 2012


Hi All,

We are interoperating, via SAML2, with an ADFS (Active Directory
Federation Services) IdP (aka Account federation server) and it
appears to go well until redirection back to the SP where we receive
the following error

SAML response contained an error.
Error from identity provider:
Status: urn:oasis:names:tc:SAML:2.0:status:Responder

Which I believe is an error returned by the ADFS IdP [1]. I have been
working with the administrator on the ADFS side and he says

> It also looks like the SAML request has Destination="https://sso.a.example.com/adfs/ls/"
> This should not be necessary and is causing an error on our end.
> Other systems we work with do not include this tag.

is this a valid concern? How can I prevent the SP (native Shibboleth
SP with Apache and Tomcat) from sending the "Destination" XML
attribute in the SAML2 request? FYI, the full request is at

http://paste.ubuntu.com/1139312/

Many thanks!

Fred.

[1] http://msdn.microsoft.com/en-us/library/hh269642%28v=prot.13%29.aspx


More information about the users mailing list