detected a problem with assertion: Unable to establish security of incoming assertion.
Christopher Bongaarts
cab at umn.edu
Fri Sep 27 21:41:00 UTC 2024
On 9/27/2024 4:00 PM, George Maynard via users wrote:
> For that issue I check and it says to consult the shibd.log file. I turned on debug and got this
> 2024-09-26 14:27:43 WARN Shibboleth.SSO.SAML2 [1] [default]: error processing incoming assertion: Invalid HTTP method (GET).
> Is there something in the shibboleth2.xml that I need to check or is there something on IDP
I believe this happens when the browser does a GET instead of a POST to
the HTTP-POST ACS URL. The two causes I've seen for this are either the
SP metadata is wrong on the IdP, or the browser is compromised and
malware is munging POSTs into GETs (but I've not seen the latter for a
long time....)
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list