Okta missing Destination in SAML response
Christopher Bongaarts
cab at umn.edu
Fri Dec 8 18:42:12 UTC 2023
Surely others have configured a Shibboleth IdP to use SAML proxy
authentication with Okta as their IdP?
We are trying to set this up (Shib IdP 4.1.7) but are getting an error
with the SAML response from Okta:
2023-12-08 12:14:58,655 - 128.101.xx.yy - ERROR
[org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:170]
- Message Handler: SAML message intended destination endpoint URI
required by binding was empty
2023-12-08 12:14:58,656 - 128.101.xx.yy - WARN
[net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:197] -
Profile Action WebFlowMessageHandlerAdaptor: Exception handling message
org.opensaml.messaging.handler.MessageHandlerException: SAML message
intended destination (required by binding) was not present
at
org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler.checkEndpointURI(ReceivedEndpointSecurityHandler.java:172)
We were able to confirm that there is no Destination attribute on the
SAML response. This seems like a bug in Okta's implementation, but not
sure how anyone else would have been able to get it working. Anyone
else tried this? Did we miss a step somewhere?
Thanks,
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list