SAML 1 TransientID Canonicalization
Nate Klingenstein
ndk at sudonym.me
Fri Feb 3 03:18:24 EST 2017
> This is saying that it looked up that transient and found no record of it ever being issued.
That part made sense to me. It was the "why": the transient identifier
was AFAIK crypto, present in the outbound POST audit stamp, and matching
to my eyes in the inbound query. I'm more curious about the last line,
but with your explanation, it's probably just the natural termination of
the flow after the error.
I only thought to ask since I know canonicalization is too confusing for
me and this(actual, surviving SAML 1 back-channel queries) seemed like
an edge case.
Logs are contiguous from a single node. There are multiple nodes in the
pool, but we got this to fail consistently, not 67% of the time.
> It also indicates that it did spot that it was SAML1...
>
> Does that help explain case sensitivity as the cause?
Naw, that was SQL columns not being consistently camel-cased.
More information about the users
mailing list