Understanding the cause of error related to parsing Issuer

Scott Cantor scott at restingparrotsoftware.com
Wed Jan 21 23:28:37 UTC 2026


>  I was hoping to get a better understanding of the following error and how to address it.  After being directed back to our SP (which is running Shibboleth) from the customer’s IdP, the user sees an error message:
>  opensaml::FatalProfileException at (https://server-running-shibboleth-sp.com/Shibboleth.sso/SAML2/POST)
> An Issuer was supplied that conflicts with previous results.

IIRC, that happens when you have a situation where the Response Issuer != the Assertion Issuer. I don't think I have ever encountered that in practice in 25 years.

Every time I think people can't implement SAML any more ridiculously, they teach me otherwise.

-- Scott



More information about the users mailing list