Troubleshooting the "Unable to decode" (IdP 3.3)

Cantor, Scott cantor.2 at osu.edu
Fri Aug 25 13:03:42 EDT 2017


On 8/25/17, 1:01 PM, "users on behalf of O'Dowd, Josh" <users-bounces at shibboleth.net on behalf of Josh.O'Dowd at mso.umt.edu> wrote:

> The request content is encrypted, obviously but the access header looks like:

It's not encrypted, not in general anyway.

> The one difference I see between these and successful GET requests to these endpoints is the successful ones all have ?
> SAMLRequest= and all the failing ones have the ?RelayState= parameter.  I don't know if that means anything important.

If there's no SAMLRequest parameter, then it's going to fail to decode, that's just an invalid request. There's nothing to log, there's just nothing there.

-- Scott




More information about the users mailing list