<p>Thanks Scott have found a workaround anyway and now trying to debug attribute retrieval. Hit the centos  / redhat 6 curl lib issue and working through using your rpm&#39;s and configuring SSL correctly.</p>
<p>NIrving</p>
<div class="gmail_quote">On Oct 6, 2011 1:32 AM, &quot;Cantor, Scott&quot; &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; wrote:<br type="attribution">&gt; On 10/5/11 12:19 AM, &quot;Nicholas Irving&quot; &lt;<a href="mailto:nirving@darkedges.com">nirving@darkedges.com</a>&gt; wrote:<br>
&gt;&gt;<br>&gt;&gt;As you can see the request contains the TARGET parameter, but as part of<br>&gt;&gt;the URL and not the POST. So the question is, is this Shibboleth being<br>&gt;&gt;true to the SAML 1.1 spec and requiring TARGET to be POST&#39;d or has it<br>
&gt;&gt;missed a trick and this is a valid request?<br>&gt; <br>&gt; The SP isn&#39;t intentionally being that strict about it, but the CGI parser<br>&gt; in 2.4 doesn&#39;t have the ability to handle both form parameters and query<br>
&gt; string parameters in a POST. It sees POST and just goes to the body.<br>&gt; That&#39;s being enhanced in 2.5.<br>&gt; <br>&gt; Not that they&#39;re following the standard, just noting it.<br>&gt; <br>&gt; -- Scott<br>
&gt; <br>&gt; --<br>&gt; To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></div>