Login target url parameter limit

Peter Schober peter.schober at univie.ac.at
Mon Feb 20 13:48:27 UTC 2023


* Pavel Šipoš <pavel.sipos at arnes.si> [2023-02-20 14:28]:
> It is actually our DS that is making redirection and not shibboleth
> SP (I checked that now with samltracer).

That shouldn't be the case with SAML 2.0, it's always the SP making
that final redirect to the IDP: The SP might want to sign the
authnRequest or put other info into it.

> As we use simplesamlphp for DS I will have to look for answer there.

First make sure you're using SAML 2.0 and not the old "WAYF" protocol
that forces usage of SAML1.

-peter


More information about the users mailing list