Issue with URL re-direct after IDP authentication - signing Assertion

Douglas E. Engert deengert at anl.gov
Thu Jul 11 16:44:34 EDT 2013


Are using IE? Sounds like a problem of a signed AuthnRequest being larger then 2K,
and IE would truncate the request at 2K.

FF or Chrome worked fine.

See

http://shibboleth.net/pipermail/users/2013-January/007862.html

   "Invalid XML error for signed AuthnRequest in IE"

http://support.microsoft.com/kb/208427



On 7/11/2013 3:17 PM, justin9 wrote:
> Hi Scott,
> The IDP has the below error in their logs -
>
> [7040/6920][Thu Jul 11 2013 16:07:32][AssertionGenerator.java][ERROR]
> preProcess() returns fatal error. <Response
> ID="_ec04f14c015a729ca1c9dca6c6a7939c7282"
> InResponseTo="_b915a4f4d795291cd6521652ca86d12e"
> IssueInstant="2013-07-11T20:07:32Z" Version="2.0"
> xmlns="urn:oasis:names:tc:SAML:2.0:protocol">
>      <ns1:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"
> xmlns:ns1="urn:oasis:names:tc:SAML:2.0:assertion">https://myidp.org/SAML2/IDP</ns1:Issuer>
>      <Status>
>          <StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Requester">
>              <StatusCode
> Value="urn:oasis:names:tc:SAML:2.0:status:RequestDenied"/>
>          </StatusCode>
>          <StatusMessage>Invalid signature.</StatusMessage>
>      </Status>
> </Response>
>
>
> this is all the info i get from them !
>
>
>
> --
> View this message in context: http://shibboleth.1660669.n2.nabble.com/Issue-with-URL-re-direct-after-IDP-authentication-signing-Assertion-tp7588400p7588430.html
> Sent from the Shibboleth - Users mailing list archive at Nabble.com.
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>

-- 

  Douglas E. Engert  <DEEngert at anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444


More information about the users mailing list