IdP initiated auth not working whereas SP initiated is ok
Luay Zakaria
luay.zakaria at gmail.com
Thu Dec 18 11:38:30 EST 2014
still waiting on confirmation from IdP on RelayState settings. in the
meantime I'm comparing the SAML2/POST contents of SP initited and IdP
initiated and I can see that the referer in the IdP initiated case is
missing the attributes ?SAMLRequest=... and &RelayState=... (whereas
they exist in the SP initiated case)
will post again once more details have been uncovered.
thanks!
On 12/18/14, 3:56 PM, "Luay Zakaria" <luay.zakaria at gmail.com> wrote:
>Actually, shibd.log is showing a successful session being created:
>2014-12-18 10:07:09 INFO Shibboleth.SessionCache [1]: new session
>created: ID (_ce47b311a1f489cb3fef260f38841a80) IdP
>(http://sts.someIDP.com/adfs/services/trust)
>Protocol(urn:oasis:names:tc:SAML:2.0:protocol)
> Address (....)
>Transaction.log is showing a matching session successfully created as
>well.
>At the sametime, native_warn.log is showing the error:
>2014-12-18 10:07:09 ERROR Shibboleth.ISAPI [14180] isapi_shib_extension:
>URL is malformed.
Then my guess would be that the RelayState is invalid and it's trying to
use it as a URL to redirect to, subsequently flagging it.
Tom already suggested that, and I saw no follow up.
-- Scott
--
To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141218/a62b5971/attachment.html
More information about the users
mailing list