Troubleshooting the "Unable to decode" (IdP 3.3)

Cantor, Scott cantor.2 at osu.edu
Wed Aug 30 17:25:27 EDT 2017


On 8/30/17, 5:20 PM, "users on behalf of O'Dowd, Josh" <users-bounces at shibboleth.net on behalf of Josh.O'Dowd at mso.umt.edu> wrote:

> Is there anything I can do to debug from the SP side of things.

There's nothing to debug, merely reproduce. The SP is fine apart from needlessly signing.

>  Looking at the SAMLRequest(once decoded), I can see that the issuer is one of our local SPs(which, as you already know is a
> Shibboleth SP)?

Well, that rules out "all requests from it fail" or you'd probably know about it. Being that it's local I suppose you can get them to stop signing since there's no reason to be.

I think it's pretty likely that something out there is accessing a URL on this server that's perhaps improperly being stuck behind the SP and is triggering a redirect that the "something" is handling badly and corrupting before following it to the IdP and then it plays a corrupt request. I don't think there's much beyond that that's knowable, but perhaps getting the user agent from a log entry would be interesting.

-- Scott




More information about the users mailing list