SAML 1 TransientID Canonicalization

Nate Klingenstein ndk at sudonym.me
Fri Feb 3 03:18:24 EST 2017


> This is saying that it looked up that transient and found no record of it ever being issued.

That part made sense to me.  It was the "why": the transient identifier 
was AFAIK crypto, present in the outbound POST audit stamp, and matching 
to my eyes in the inbound query.  I'm more curious about the last line, 
but with your explanation, it's probably just the natural termination of 
the flow after the error.

I only thought to ask since I know canonicalization is too confusing for 
me and this(actual, surviving SAML 1 back-channel queries) seemed like 
an edge case.

Logs are contiguous from a single node.  There are multiple nodes in the 
pool, but we got this to fail consistently, not 67% of the time.

> It also indicates that it did spot that it was SAML1...
>
> Does that help explain case sensitivity as the cause?

Naw, that was SQL columns not being consistently camel-cased.


More information about the users mailing list