Error decoding authentication request message & SAML response contained an error

Cantor, Scott cantor.2 at osu.edu
Mon Jul 1 13:46:16 EDT 2013


> I first encountered the following problem: "Error decoding authentication
> request message" when trying to browse  https://ans.247.com/secure. It
> looks like the authentication request is sent to the Idp, but no authentication
> response since the url I get back for the above error message is
> https://amlib.co.uk:8443/idp/profile/SAML2/Redirect/SSO . When I also
> looked at the shibd log, I could read  "no metadata found, can't establish
> identity of issuer (https://amlib.co.uk/idp:8443/shibboleth)".  I thought that
> it was an issue at the level of metadata configuration in Shibboleth2.xml file.

Those errors are very different unrelated things.

> Error from identity provider:
> 
> 	Status: urn:oasis:names:tc:SAML:2.0:status:Responder
> 	Sub-Status: urn:oasis:names:tc:SAML:2.0:status:AuthnFailed

Your IdP has no login handler configured to do anything, apparently. Search the archive and you'll find many messages related to the issue, or more to the point just read the documentation on configuring the authentication method.

-- Scott




More information about the users mailing list