IDP3.2.1 Unable to decode incoming request
Käfer Thomas
thomas.kaefer at fh-campuswien.ac.at
Tue Jul 12 07:32:57 EDT 2016
Dear fellow Shibboleth users!
We're currently in the progress of setting up a new IDP 3.2.1 and in recent days we've seen a strange behavior of requests getting lost and users being forwarded to the "stale request" error page. This happens for Firefox browsers reliably EVERY TIME, and for others sometimes, but in other browsers the error can be circumvented by clearing cookies for both the SP and IDP domains.
This is what shows up in the idp-process.log file when a session is lost:
2016-07-12 12:14:20,908 - ERROR [org.opensaml.profile.action.impl.DecodeMessage:73] - Profile Action DecodeMessage: Unable to decode incoming request
org.opensaml.messaging.decoder.MessageDecodingException: This message decoder only supports the HTTP POST method
at org.opensaml.saml.saml2.binding.decoding.impl.HTTPPostDecoder.doDecode(HTTPPostDecoder.java:57)
2016-07-12 12:14:20,910 - WARN [org.opensaml.profile.action.impl.LogEvent:76] - An error event occurred while processing the request: UnableToDecode
The browser does not seem to be doing anything differently as to when it works, it sends the same POST request but does not get the set-cookie header it normally should and therefore after sending username password in a second POST the server forwards him to the stale request page.
Has anybody seen this before? This problem seems to be new to me and I have not intentionally changed the IDPs configuration since before it showed up.
Thank you,
Kind Regards,
Thomas Käfer
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160712/77cdb30f/attachment-0001.html>
More information about the users
mailing list