Troubleshooting the "Unable to decode" (IdP 3.3)
Cantor, Scott
cantor.2 at osu.edu
Fri Aug 25 13:27:38 EDT 2017
On 8/25/17, 1:21 PM, "users on behalf of O'Dowd, Josh" <users-bounces at shibboleth.net on behalf of Josh.O'Dowd at mso.umt.edu> wrote:
> Sorry , just hashed then?
No, deflated and encoded, nothing irreversible.
> Actually, there is a SAMLRequest parameter that I missed, coming after the RelayState parameter, and now I see that only some
> of the failed requests have a leading RelayState parameter.
> Sample access entry for failed request:
> [25/Aug/2017:09:24:05 -0600] TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 "GET /idp/profile/SAML2/Redirect/SLO?
> RelayState=ss:mem:18e8f777deec8579d5adfb48fbaf6d9ae296df30c777408c7058488b5509bd70&
That's a Shibboleth SP request (that's my relay state convention). If Facebook is using my code, I will be shocked, somewhat pissed off, and maybe amused all at the same time.
That also means the request wouldn't cause a decoding error because mine aren't broken. So I think you're correlating to the wrong request perhaps, or I can't really explain how that's possible or what the error is.
-- Scott
More information about the users
mailing list