SP ACS extra query string parameter rejected by IdPv3, not rejected by IdPv2

Waldbieser, Carl waldbiec at lafayette.edu
Sat Mar 12 12:17:38 EST 2016


I have an SP that sends a an "AuthnRequest" with an "AssertionConsumerServiceURL" attribute ending in "/AssertionConsumerService.aspx?sid=1699&gid=2".

The metadata for this SP lists a single "AssertionConsumerService" element with a "Location" attribute ending "/AssertionConsumerService.aspx?sid=1699".

Our current Shibboleth IdPv2 service seems to accept this slight difference without a problem.  The IdpV3 service I have in integration testing fails to find a matching ACS.  If I manually tweak the metadata to include the extra "gid" parameter, IdPv3 *does* find the matching ACS endpoint and authentication succeeds.

Which behavior is correct?  IdPv2 being tolerant of the extra parameter, or IdPv3 rejecting it?  Is this a bug in IdPv3, or is this an issue I need to bring up with the service provider?

I am using idp_version: 3.2.1

Thanks,
Carl Waldbieser
ITS Identity Management
Lafayette College


More information about the users mailing list