CA Site Minder IDP : Shibboleth SP

Bhattacharjee, Raja Raja.Bhattacharjee at Level3.com
Tue Apr 8 20:55:08 EDT 2014


Thanks Scott. 

A caveat...when I said the template I have put below is using for other IDPs...for all those IDPs I have relayState set to ss:mem. With CA SiteMinder since the ss:mem did not work I tried cookie.

When you say to check the relay handling, is there any easy way to do this within shibboleth configuration and logs or do I capture packets using say tcpsump?

Raja

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Tuesday, April 08, 2014 6:45 PM
To: Shib Users
Subject: Re: CA Site Minder IDP : Shibboleth SP

On 4/8/14, 8:24 PM, "Bhattacharjee, Raja" <Raja.Bhattacharjee at Level3.com>
wrote:

> 
>Instead of redirecting to
>https://collaboration-sso.cfer.com/acme/
><https://collaboration-sso.cfer.com/acme/> it is doing the following
> 
>2014-04-08 23:47:11 DEBUG Shibboleth.SSO.SAML2 [3]: ACS returning via 
>redirect to:
>https://collaboration-sso.cfer.com/
>I have tried ss:mem as relayState with the same end result. The above 
>application override template is working for all other IDP providers 
>that we federate with.

Assuming that's true, I guess I'd verify the relay state handling that's going on and see if you're getting back what you're sending.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list