Issue with URL re-direct after IDP authentication - signing Assertion
Douglas E. Engert
deengert at anl.gov
Thu Jul 11 16:44:34 EDT 2013
Are using IE? Sounds like a problem of a signed AuthnRequest being larger then 2K,
and IE would truncate the request at 2K.
FF or Chrome worked fine.
See
http://shibboleth.net/pipermail/users/2013-January/007862.html
"Invalid XML error for signed AuthnRequest in IE"
http://support.microsoft.com/kb/208427
On 7/11/2013 3:17 PM, justin9 wrote:
> Hi Scott,
> The IDP has the below error in their logs -
>
> [7040/6920][Thu Jul 11 2013 16:07:32][AssertionGenerator.java][ERROR]
> preProcess() returns fatal error. <Response
> ID="_ec04f14c015a729ca1c9dca6c6a7939c7282"
> InResponseTo="_b915a4f4d795291cd6521652ca86d12e"
> IssueInstant="2013-07-11T20:07:32Z" Version="2.0"
> xmlns="urn:oasis:names:tc:SAML:2.0:protocol">
> <ns1:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"
> xmlns:ns1="urn:oasis:names:tc:SAML:2.0:assertion">https://myidp.org/SAML2/IDP</ns1:Issuer>
> <Status>
> <StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Requester">
> <StatusCode
> Value="urn:oasis:names:tc:SAML:2.0:status:RequestDenied"/>
> </StatusCode>
> <StatusMessage>Invalid signature.</StatusMessage>
> </Status>
> </Response>
>
>
> this is all the info i get from them !
>
>
>
> --
> View this message in context: http://shibboleth.1660669.n2.nabble.com/Issue-with-URL-re-direct-after-IDP-authentication-signing-Assertion-tp7588400p7588430.html
> Sent from the Shibboleth - Users mailing list archive at Nabble.com.
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
--
Douglas E. Engert <DEEngert at anl.gov>
Argonne National Laboratory
9700 South Cass Avenue
Argonne, Illinois 60439
(630) 252-5444
More information about the users
mailing list