IdP initiated auth not working whereas SP initiated is ok

Luay Zakaria luay.zakaria at gmail.com
Thu Dec 18 11:38:30 EST 2014


still waiting on confirmation from IdP on RelayState settings. in the
meantime I'm comparing the SAML2/POST contents of SP initited and IdP
initiated and I can see that the referer in the IdP initiated case is
missing the attributes ?SAMLRequest=...   and   &RelayState=...    (whereas
they exist in the SP initiated case)

will post again once more details have been uncovered.

thanks!


On 12/18/14, 3:56 PM, "Luay Zakaria" <luay.zakaria at gmail.com> wrote:



>Actually, shibd.log is showing a successful session being created:

>2014-12-18 10:07:09 INFO Shibboleth.SessionCache [1]: new session

>created: ID (_ce47b311a1f489cb3fef260f38841a80) IdP

>(http://sts.someIDP.com/adfs/services/trust)

>Protocol(urn:oasis:names:tc:SAML:2.0:protocol)

> Address (....)

>Transaction.log is showing a matching session successfully created as

>well.

>At the sametime, native_warn.log is showing the error:

>2014-12-18 10:07:09 ERROR Shibboleth.ISAPI [14180] isapi_shib_extension:

>URL is malformed.



Then my guess would be that the RelayState is invalid and it's trying to
use it as a URL to redirect to, subsequently flagging it.



Tom already suggested that, and I saw no follow up.



-- Scott



--

To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141218/a62b5971/attachment.html 


More information about the users mailing list