<div style>We are using browser post.  The URL that is generating the SAML 1 request looks identical minus a state ID (noted below) ... so I don&#39;t think it is a corrupted request.  The request lengths are less than 600 characters too, so there isn&#39;t anything like that in play.</div>
<div style><br></div><div style>Plus, the assertion states the Audience correctly in both cases.</div><div style><br></div><div style>Could there be Attribute Release Policies in play (that I should have the admin check)?</div>
<div><br></div><div>good:</div><div><div><br></div><div><a href="https://fed.it.northwestern.edu/shibboleth-idp/SSO?providerId=https%3A%2F%2Fadeassodev.northwestern.edu%2Fsimplesaml%2Fmodule.php%2Fsaml%2Fsp%2Fmetadata.php%2Fnu_passport&amp;shire=https%3A%2F%2Fadeassodev.northwestern.edu%2Fsimplesaml%2Fmodule.php%2Fsaml%2Fsp%2Fsaml1-acs.php%2Fnu_passport&amp;target=">https://fed.it.northwestern.edu/shibboleth-idp/SSO?providerId=https%3A%2F%2Fadeassodev.northwestern.edu%2Fsimplesaml%2Fmodule.php%2Fsaml%2Fsp%2Fmetadata.php%2Fnu_passport&amp;shire=https%3A%2F%2Fadeassodev.northwestern.edu%2Fsimplesaml%2Fmodule.php%2Fsaml%2Fsp%2Fsaml1-acs.php%2Fnu_passport&amp;target=</a><span class="Apple-style-span" style="background-color:rgb(255,255,0)">_79ae1cd2ef1fe78afc1c9daa3e363f65c7df4c6cfd</span>%3Ahttps%3A%2F%<a href="http://2Fadeassodev.northwestern.edu">2Fadeassodev.northwestern.edu</a>%2Fsimplesaml%2Fmodule.php%2Fcore%2Fas_login.php%3FAuthId%3Dnu_passport%26ReturnTo%3Dhttps%253A%252F%<a href="http://252Fadeassodev.northwestern.edu">252Fadeassodev.northwestern.edu</a>%252Fsimplesaml%252Fmodule.php%252Fcore%252Fauthenticate.php%253Fas%253Dnu_passport</div>
<div><br></div><div>bad:</div><div><br></div><div><a href="https://fed.it.northwestern.edu/shibboleth-idp/SSO?providerId=https%3A%2F%2Fadeassodev.northwestern.edu%2Fsimplesaml%2Fmodule.php%2Fsaml%2Fsp%2Fmetadata.php%2Fnu_passport&amp;shire=https%3A%2F%2Fadeassodev.northwestern.edu%2Fsimplesaml%2Fmodule.php%2Fsaml%2Fsp%2Fsaml1-acs.php%2Fnu_passport&amp;target=">https://fed.it.northwestern.edu/shibboleth-idp/SSO?providerId=https%3A%2F%2Fadeassodev.northwestern.edu%2Fsimplesaml%2Fmodule.php%2Fsaml%2Fsp%2Fmetadata.php%2Fnu_passport&amp;shire=https%3A%2F%2Fadeassodev.northwestern.edu%2Fsimplesaml%2Fmodule.php%2Fsaml%2Fsp%2Fsaml1-acs.php%2Fnu_passport&amp;target=</a><span class="Apple-style-span" style="background-color:rgb(255,255,0)">_7e6a2ae72b065cb1ed894c2500322d12b6ed0a0ff8</span>%3Ahttps%3A%2F%<a href="http://2Fadeassodev.northwestern.edu">2Fadeassodev.northwestern.edu</a>%2Fsimplesaml%2Fmodule.php%2Fcore%2Fas_login.php%3FAuthId%3Dnu_passport%26ReturnTo%3Dhttps%253A%252F%<a href="http://252Fadeassodev.northwestern.edu">252Fadeassodev.northwestern.edu</a>%252Fsimplesaml%252Fmodule.php%252Fcore%252Fauthenticate.php%253Fas%253Dnu_passport</div>
</div><br clear="all">Mike Basil<br>312.961.7798<br>

<br><br><div class="gmail_quote">On Mon, Apr 2, 2012 at 15:09, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">&gt; However, when the client (subject web browser) is off campus the<br>
&gt; AttributeStatement is not sent to my SP.<br>
<br>
</div>There&#39;s nothing that could cause that unless the difference is resulting in a corrupted request that doesn&#39;t actually identify the SP (or misidentifies it) and results in some default behavior.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br>