Okta missing Destination in SAML response

Christopher Bongaarts cab at umn.edu
Fri Dec 8 18:42:12 UTC 2023


Surely others have configured a Shibboleth IdP to use SAML proxy 
authentication with Okta as their IdP?

We are trying to set this up (Shib IdP 4.1.7) but are getting an error 
with the SAML response from Okta:

2023-12-08 12:14:58,655 - 128.101.xx.yy - ERROR 
[org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler:170] 
- Message Handler:  SAML message intended destination endpoint URI 
required by binding was empty
2023-12-08 12:14:58,656 - 128.101.xx.yy - WARN 
[net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:197] - 
Profile Action WebFlowMessageHandlerAdaptor: Exception handling message
org.opensaml.messaging.handler.MessageHandlerException: SAML message 
intended destination (required by binding) was not present
     at 
org.opensaml.saml.common.binding.security.impl.ReceivedEndpointSecurityHandler.checkEndpointURI(ReceivedEndpointSecurityHandler.java:172)

We were able to confirm that there is no Destination attribute on the 
SAML response.  This seems like a bug in Okta's implementation, but not 
sure how anyone else would have been able to get it working.  Anyone 
else tried this?  Did we miss a step somewhere?

Thanks,

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%



More information about the users mailing list