Understanding the cause of error related to parsing Issuer

david.jones at equorum.com david.jones at equorum.com
Wed Jan 21 22:13:21 UTC 2026


Hello,

 

I was hoping to get a better understanding of the following error and how to
address it.  After being directed back to our SP (which is running
Shibboleth) from the customer's IdP, the user sees an error message:

 

opensaml::FatalProfileException at
(https://server-running-shibboleth-sp.com/Shibboleth.sso/SAML2/POST)

An Issuer was supplied that conflicts with previous results.

 

The shibd.log file (with debug logging enabled) looks like:

 

2026-01-07 08:13:20 DEBUG OpenSAML.MessageDecoder.SAML2 [1] [default]:
message from (http://customer-idp-site.com/metadata)

2026-01-07 08:13:20 DEBUG OpenSAML.MessageDecoder.SAML2 [1] [default]:
searching metadata for message issuer...

2026-01-07 08:13:20 DEBUG OpenSAML.MessageDecoder.SAML2 [1] [default]: no
request/response correlation cookie found

2026-01-07 08:13:20 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [1]
[default]: evaluating message flow policy (correlation off, replay checking
on, expiration 60)

2026-01-07 08:13:20 DEBUG OpenSAML.SecurityPolicyRule.MessageFlow [1]
[default]: ignoring InResponseTo, correlation checking is disabled

2026-01-07 08:13:20 DEBUG XMLTooling.StorageService [1] [default]: inserted
record (id-13d8a44f44ab5d8eb2490eca8610b65ccbdd5de8) in context
(MessageFlow) with expiration (1767795439)

2026-01-07 08:13:20 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]
[default]: validating signature profile

2026-01-07 08:13:20 DEBUG XMLTooling.KeyInfoResolver.Inline [1] [default]:
resolving ds:X509Certificate

2026-01-07 08:13:20 DEBUG XMLTooling.KeyInfoResolver.Inline [1] [default]:
resolved 1 certificate(s)

2026-01-07 08:13:20 DEBUG XMLTooling.KeyInfoResolver.Inline [1] [default]:
resolved 0 CRL(s)

2026-01-07 08:13:20 DEBUG XMLTooling.TrustEngine.ExplicitKey [1] [default]:
attempting to validate signature with the peer's credentials

2026-01-07 08:13:20 DEBUG XMLTooling.TrustEngine.ExplicitKey [1] [default]:
signature validated with credential

2026-01-07 08:13:20 DEBUG OpenSAML.SecurityPolicyRule.XMLSigning [1]
[default]: signature verified against message issuer

2026-01-07 08:13:20 DEBUG Shibboleth.SSO.SAML2 [1] [default]: processing
message against SAML 2.0 SSO profile

2026-01-07 08:13:20 DEBUG Shibboleth.SSO.SAML2 [1] [default]: extracting
issuer from SAML 2.0 assertion

2026-01-07 08:13:20 WARN Shibboleth.SSO.SAML2 [1] [default]: detected a
problem with assertion: An Issuer was supplied that conflicts with previous
results.

2026-01-07 08:13:20 WARN Shibboleth.SSO.SAML2 [1] [default]: error
processing incoming assertion: An Issuer was supplied that conflicts with
previous results.

 

I also have a .har file captured, SAML Tracer output logs, and configuration
xml files saved to better inspect the http response if that is helpful.

 

-David



 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260121/9420b540/attachment.htm>


More information about the users mailing list