SP ACS extra query string parameter rejected by IdPv3, not rejected by IdPv2
Waldbieser, Carl
waldbiec at lafayette.edu
Sat Mar 12 12:17:38 EST 2016
I have an SP that sends a an "AuthnRequest" with an "AssertionConsumerServiceURL" attribute ending in "/AssertionConsumerService.aspx?sid=1699&gid=2".
The metadata for this SP lists a single "AssertionConsumerService" element with a "Location" attribute ending "/AssertionConsumerService.aspx?sid=1699".
Our current Shibboleth IdPv2 service seems to accept this slight difference without a problem. The IdpV3 service I have in integration testing fails to find a matching ACS. If I manually tweak the metadata to include the extra "gid" parameter, IdPv3 *does* find the matching ACS endpoint and authentication succeeds.
Which behavior is correct? IdPv2 being tolerant of the extra parameter, or IdPv3 rejecting it? Is this a bug in IdPv3, or is this an issue I need to bring up with the service provider?
I am using idp_version: 3.2.1
Thanks,
Carl Waldbieser
ITS Identity Management
Lafayette College
More information about the users
mailing list