Troubleshooting the "Unable to decode" (IdP 3.3)
Brent Putman
putmanb at georgetown.edu
Wed Aug 30 15:25:48 EDT 2017
On 8/30/17 11:23 AM, Cantor, Scott wrote:
>> The SAMLRequest parameter value from the above HTTPRequest which
>> caused the above error. This was decoded using the http://rnd.feide.no/
>> SAML2 debugger tool:
> That means it could not have caused that ZIP exception. Thus my conclusion.
Well, the FEIDE tool is absolutely lax about DEFLATE, since they
dynamically support Redirect and POST on the same tool, with no options
to specify what it is:
> Paste in a SAML message encoded with the HTTP-POST or HTTP-REDIRECT
> encoding. You can both use the full URL that you copied from
> LiveHTTPHeaders, or you can paste in only the SAMLRequest or
> SAMLResponse parameter. It will be automatically detected whether you
> post a URL or the value it self and whether you post a HTTP-REDIRECT
> or HTTP-POST encoded value. enjoy!
So it's going to accept invalid inputs for either binding and still
decode them.
But, taking another view: since it seems we know (correct?) this is a
Shib SP, and that's pretty well established to not be screwing up the
Redirect binding, it could be that the sample HTTP request sent in the
other message is miscorrelated with the OpenSAML errors.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170830/7e1568be/attachment.html>
More information about the users
mailing list