Troubleshooting the "Unable to decode" (IdP 3.3)

Brent Putman putmanb at georgetown.edu
Wed Aug 30 15:40:58 EDT 2017



On 8/30/17 3:19 PM, Brent Putman wrote:
>
>
>
>>  
>>
>> The GET component of HTTPRequest from the httpd-access.log which
>> caused the above error:
>>
>
> I'll spend a few minutes investigating this and let you know what I find.


That message is DEFLATEd and is a valid Redirect binding message, as
far as I can tell.  It isn't merely Base64-encoded like a POST message
would be.  It is successfully decoded by the OneLogin tool, which
unlike the FEIDE tool requires it to be DEFLATEd  (I tested with a
valid POST binding message, and it fails as expected).

So I tend to agree with Scott that there may be some miscorrelation
here of the HTTP log and OpenSAML error in the IdP.   It also appears
the HTTP log was from a Shib SP, whose Redirect binding impl is known
to work with the Shib IdP, so that's more evidence for that suspicion.

Can you please double check the messages you are pulling out of the
HTTP log and make sure you're getting one of them that causes the error?

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170830/cad383b8/attachment.html>


More information about the users mailing list