SP shibsession looping

Nate Klingenstein ndk at internet2.edu
Tue Aug 19 10:05:05 EDT 2014


Savitha,

We have configured Shibboleth service provider on win 2008 -IIS7 in  our organization and it will be interacting with an
external IDP  belongs other organization (not shibboleth it is openId )that supports SAML 2.0(Microsoft product) .

This doesn't make much sense to me.  OpenID is kinda sorta a protocol suite and Shibboleth is a software product.  SAML 2.0 is not a Microsoft product, but a widely used standard.  Could you try rephrasing what you're trying to do?

When we browse the shib secured application URL( application which is configured in shib-SP configuration file),
it is redirecting to other organization IDP  login page for authorization.Once authentication details provided, the SSO control is returning back to locally configured SP  but instead redirecting to our shib secured application page (requested page) the request is looping and refreshing SAML request with different  "relay state " value  highlighted as below.

Does this resource protected by this SP work with other IdP's?  If so, I think your problem is that the IdP is encoding colon in the RelayState parameter in a strange way.

All the suggestions Scott gave will help you to resolve the problem.  These are just a couple breadcrumbs from experience.

Thanks,
Nate.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140819/b8e573ce/attachment.html 


More information about the users mailing list