Troubleshooting the "Unable to decode" (IdP 3.3)

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Wed Aug 30 12:51:37 EDT 2017


Thanks Scott,

I pretty confused, then.  In the httpd-access log, I am matching on the IP address and timestamp I get from the error, to find the the incoming HTTPRequest.  I am not seeing any other requests that I could be missing.

I understand your conclusion and I appreciate your time.

Thanks again.

Josh

-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Wednesday, August 30, 2017 9:23 AM
To: Shib Users <users at shibboleth.net>
Subject: RE: Troubleshooting the "Unable to decode" (IdP 3.3)

> I finally was able to run a request from our httpd-access logs for a 
> request where IdP erroring on the decoding.  I would really appreciate 
> if someone could take a look at the error and the SAMLRequest 
> parameter, decoded from the HTTPRequest that caused the error.  Is it 
> the HTTPRequest that the inflater is calling “invalid”, or the 
> SAMLRequest portion

Neither. You are not correlating the errors to the right requests, you can't be.

> The SAMLRequest parameter value from the above HTTPRequest which 
> caused the above error.  This was decoded using the 
> http://rnd.feide.no/
> SAML2 debugger tool:

That means it could not have caused that ZIP exception. Thus my conclusion.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list