Question on response status codes on auth failure
Stefan Santesson
stefan at aaa-sec.com
Mon Jun 22 10:46:55 EDT 2015
I got a question from helpdesk on our test IdP.
They are asking why they get a ³Requester² error status code when the
underlying reason is AuthnFailed.
<saml2p:Status>
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Requester">
<saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:AuthnFailed"/>
</saml2p:StatusCode>
<saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage>
</saml2p:Status>
This seems to be the default configuration in error.xml
Why is it so?
The major status code seems to propose that there is an error on behalf of
the requester, which clearly is not the case.
Is it safe to reconfigure this, or can this create other problems?
/Stefan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150622/07a0b2a4/attachment.html>
More information about the users
mailing list