detected a problem with assertion: Unable to establish security of incoming assertion.
George Maynard
George.Maynard at ltimindtree.com
Mon Sep 30 18:27:09 UTC 2024
Thanks for the information, do you know what I should be looking for in the metadata?
Regards & Thanks!
George Maynard
DBA, Infrastructure Services
LTIMindtree Canada
2810 Matheson Boulevard E. Suite 500
Mississauga, ON Canada L4W 4X7
C +1 (416) 526-4034
LinkedIn | Twitter
OOO:
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Christopher Bongaarts via users
Sent: September 27, 2024 5:41 PM
To: users at shibboleth.net
Cc: Christopher Bongaarts <cab at umn.edu>
Subject: Re: detected a problem with assertion: Unable to establish security of incoming assertion.
Caution - This email is from an external source. Please do not click on links or attachments if sender is unknown or from known person but the content is unusual. Never share your user ID or password under any circumstances.
On 9/27/2024 4:00 PM, George Maynard via users wrote:
> For that issue I check and it says to consult the shibd.log file. I
> turned on debug and got this
> 2024-09-26 14:27:43 WARN Shibboleth.SSO.SAML2 [1] [default]: error processing incoming assertion: Invalid HTTP method (GET).
> Is there something in the shibboleth2.xml that I need to check or is
> there something on IDP
I believe this happens when the browser does a GET instead of a POST to the HTTP-POST ACS URL. The two causes I've seen for this are either the SP metadata is wrong on the IdP, or the browser is compromised and malware is munging POSTs into GETs (but I've not seen the latter for a long time....)
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
--
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
________________________________
The contents of this e-mail and any attachment(s) may contain confidential or privileged information for the intended recipient(s). Unintended recipients are prohibited from taking action on the basis of information in this e-mail and using or disseminating the information, and must notify the sender and delete it from their system. LTIMindtree will not accept responsibility or liability for the accuracy or completeness of, or the presence of any virus or disabling code in this e-mail.
More information about the users
mailing list