Issue with URL re-direct after IDP authentication - signing Assertion

Justin Russo justin9 at ymail.com
Thu Jul 11 11:11:39 EDT 2013


so then if its signing , then i'm still not redirected to my page after login.

and the behaviour when i paste my url again and enter i get to my page and i see all the below details in my shib 

2013-07-11 11:10:06 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]: signing the message
2013-07-11 11:10:06 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]: message encoded, sending redirect to client
2013-07-11 11:10:07 DEBUG Shibboleth.Listener [1]: dispatching message (default/SAML2/POST)
2013-07-11 11:10:07 DEBUG OpenSAML.MessageDecoder.SAML2POST [1]: validating input
2013-07-11 11:10:07 DEBUG OpenSAML.MessageDecoder.SAML2POST [1]: decoded SAML message:
<Response xmlns="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://nihcc.triroundup.com/Shibboleth.sso/SAML2/POST" ID="_133f856c9bdc1f14b2e483c50e9345371faf" InResponseTo="_16e3f0cad140df15213ecd95a5fe866a" IssueInstant="2013-07-11T15:10:07Z" Version="2.0">

    <ns1:Issuer xmlns:ns1="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">https://myidp.org/SAML2/IDP</ns1:Issuer>

    <Status>

        <StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/>

    </Status>

    

<ns2:EncryptedAssertion xmlns:ns2="urn:oasis:names:tc:SAML:2.0:assertion"><xenc:EncryptedData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#" Type="http://www.w3.org/2001/04/xmlenc#Element"><xenc:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/><ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">

<xenc:EncryptedKey xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"><xenc:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/><xenc:CipherData><xenc:CipherValue>awxUUNnFJl3pzrsPUSbmGFyzB/iO4EAYKeF4Xa71oiwDy7iRw1vipjeuLIV8mxLqrQ9+NJRdLZ0v

QCH2fv65ZsF0EWdXrfnLD42bpskCfbCUv8hY3Z3H6f9Z6+JBffCip+EcA7Q/DX980jbgrPjoNxqM



________________________________
 From: "Cantor, Scott" <cantor.2 at osu.edu>
To: Shib Users <users at shibboleth.net> 
Sent: Thursday, July 11, 2013 11:05 AM
Subject: RE: Issue with URL re-direct after IDP authentication - signing Assertion
 

> I see the below on my shib log after first attempt , clearly it doesnt sign -

Clearly it is.

> 2013-07-11 10:59:56 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1]:
> signing the message

It's signing. What do you think signing the request means and why do you think you need to do it?

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130711/ed375809/attachment.html 


More information about the users mailing list