/Shibboleth.sso/Login protected, but /Shibboleth.sso/SAML2/POST doesn't seem to be protected

Cantor, Scott cantor.2 at osu.edu
Mon Jan 21 19:25:34 EST 2013


On 1/21/13 7:17 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>On 1/21/13 6:56 PM, "Luay Zakaria" <luay.zakaria at gmail.com> wrote:
>>
>>With the primary (default) site  I am able to browse to
>>/Shibboleth.sso/Login and I am redirected properly,
>>
>>also, when I navigate to /Shibboleth.sso/SAML2/POST I receive the
>>expected message
>> "opensaml::BindingException... ...Invalid HTTP method (GET)."
>
>You can't just access that URL, that's a SAML endpoint and it's POST only.
>You can't get that error unless you misuse it and send it a GET.

Oops, I misread your question, I see you meant that that was "expected" as
opposed to the overridden case.

The best thing to do is to not use overrides. Once that works, you can
start worrying about overrides.

-- Scott




More information about the users mailing list