WARN message with AuthnRequest not signed but metadata configured to not require signing

Brent Putman putmanb at georgetown.edu
Tue Apr 29 03:59:41 UTC 2025


On 4/28/25 11:07 PM, Lipscomb, Gary via users wrote:
> I'm getting this WARN message
>
> 2025-04-29 12:46:35,043 - 10.9.246.182 - WARN 
> [org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:219] 
> - Signature algorithm could not be extracted from request, cannot 
> build simple signature content
>
>
> Have I missed a setting somewhere?
>

No, you haven't missed a setting.  5.1.4 introduced a spurious log 
warning as part of a bug fix. Workaround for configuring logging is 
covered in the release notes (OSJ-429):


https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199500367/ReleaseNotes


Will be addressed properly in the next release.


--Brent


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250428/09700475/attachment.htm>


More information about the users mailing list