Afternoon,<br>Have an interesting problem. Have Oracle Identity Federation 11g as my IDP with Shibboleth 2.4.3 SP to use SAML 1.1. I have managed to find all the necessary metadata changes required to do the integration and it works, if and only if I manually insert a TARGET value to the POST data via Firefox and Tamper Data.<br>
<br>After being redirected from the SP to the IDP and I successfully authenticate, the IDP generates the SAML Assertion and posts to<br><a href="https://id.xxxxx.com:8443/Shibboleth.sso/SAML/POST?TARGET=%2Fsecure%2F">https://id.xxxxx.com:8443/Shibboleth.sso/SAML/POST?TARGET=%2Fsecure%2F</a><br>
<br>As you can see the request contains the TARGET parameter, but as part of the URL and not the POST. So the question is, is this Shibboleth being true to the SAML 1.1 spec and requiring TARGET to be POST'd or has it missed a trick and this is a valid request?<br>
<br>I know I can use SAML 2, but I have a requirement to test against a SAML 1.1 SP and so I took this opportunity to learn how to deploy and configure Shibboleth.<br><br>Regards<br>-- <br><table border="0">
        <tbody><tr><td style="font-family:verdana,sans-serif"><font size="2">Nicholas Irving<br>Simple, Accurate, Secure. <br><a href="tel:04%200007%200562" value="+61400070562" target="_blank">04 0007 0562</a><br>
<a href="http://www.darkedges.com/?gmail" target="_blank">http://www.darkedges.com/</a></font></td>
<td valign="top"><br></td><td><img src="http://www.darkedges.com/images/logo.jpg"></td></tr>
</tbody></table><br>