RequesterID error on Azure/Shib IdP integration

Dave Perry d.perry1 at yorksj.ac.uk
Mon Mar 4 12:52:53 UTC 2024


I am part way through having Shibboleth use Azure/SAML instead of LDAP for its primary lookup.
I have several webapps successfully getting their data from Azure (now Entra) attributes, and signing in fine.

BUT one of these webapps (Connect2 by Lorensberg, a booking system) doesn't have an HTTP URL in its RequesterID element. The IdP using LDAP is not bothered about this, but Entra is - and throws this error when requests to sign onto it are processed:

XML Element 'RequesterID' in XML namespace 'urn:oasis:names:tc:SAML:2.0:protocol' in the SAML message must be a URI

Is this something I can suppress somewhere in the IdP? Or do I need to go back to the supplier and tell them to fix it in a future release (which will delay the rollout of 365 based shibboleth sso).


Thanks
Dave
_________________________________________________

Dave Perry
Application Analyst  |  Innovation & Technology Services

York St John University

Lord Mayor’s Walk, York, YO31 7EX
T: +44(0)1904 876 0000
d.perry1 at yorksj.ac.uk<mailto:d.perry1 at yorksj.ac.uk>  |  www.yorksj.ac.uk<http://www.yorksj.ac.uk>

[cid:09127e3d-a86d-4586-8ca6-e0f4fb5a4751]
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240304/d0d9743d/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Outlook-rafkqeus.png
Type: image/png
Size: 12155 bytes
Desc: Outlook-rafkqeus.png
URL: <http://shibboleth.net/pipermail/users/attachments/20240304/d0d9743d/attachment.png>


More information about the users mailing list