<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Before I confuse everyone, here is the actual AuthnRequest sent by SugarCRM…<div><br></div><div><div><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" ID="_89a3b55aa73d637c4978" Version="2.0" IssueInstant="2013-02-07T11:48:48Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" AssertionConsumerServiceURL="<a href="https://trial.sugarcrm.com/rvufhi7392/index.php?module=Users&action=Authenticate">https://trial.sugarcrm.com/rvufhi7392/index.php?module=Users&action=Authenticate</a>"><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">php-saml</saml:Issuer></div><div><samlp:NameIDPolicy xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" AllowCreate="true"></samlp:NameIDPolicy></div><div><samlp:RequestedAuthnContext xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" Comparison="exact"><saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml:AuthnContextClassRef></samlp:RequestedAuthnContext></div><div></samlp:AuthnRequest></div><div><br></div><div>Apologies</div><div>Glenn</div><div apple-content-edited="true">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><div><a href="http://www.edugate.ie">Edugate</a> Operations</div><div><a href="http://www.heanet.ie">HEAnet Limited</a>, Ireland's Education and Research Network - </div><div>1st Floor, 5 George's Dock, IFSC, Dublin 1</div><div>Registered in Ireland, no 275301 tel: +353-1-6609040 fax: +353-1-6603666</div></div></div>
</div>
<br><div><div>On 7 Feb 2013, at 11:35, Glenn Wearen wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">The character before the 'action' was indeed an ampersand, and this is rejected by the IdP. When I urlencode it manually (using the <a href="https://rnd.feide.no/simplesaml/module.php/saml2debug/debug.php">Feide SAML debugger</a>) the IdP parses it.<div>Thanks</div><div>Glenn<br><div><br></div><div><br><div>Edugate Operations<br>HEAnet Limited, Ireland's Education and Research Network - <br>1st Floor, 5 George's Dock, IFSC, Dublin 1<br>Registered in Ireland, no 275301 tel: +353-1-6609040 fax: +353-1-6603666<br></div><br><div><div>On 7 Feb 2013, at 10:31, Ian Young wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div><br>On 7 Feb 2013, at 09:54, Glenn Wearen <<a href="mailto:glenn.wearen@heanet.ie">glenn.wearen@heanet.ie</a>> wrote:<br><br><blockquote type="cite">Slight correction, it is the ampersand that I have urlencoded, not the question mark.<br></blockquote><br>The example you posted doesn't contain an ampersand. If the character before the "action" was an ampersand, that would be invalid XML, which is what the IdP is reporting.<br><br>As to whether the "right" answer is for the SP to URL encode such an ampersand as %25 within the XML, in the hope that it won't be decoded prior to being used in a URL, I'm not sure. I have seen that done, but if you don't have control over what the SP is generating then that may be moot.<br><br>There was a change in behaviour in this area in the IdP at some point in the 2.X series. I want to say something like 2.2.0, but I can't see the specific issue in the release notes; it may have been a side-effect of fixing something else and perhaps someone else can remember the details. We've also had related issues in the discovery service code. I do remember that we were fairly confident that the IdP was doing the right thing now, though.<br><br><span class="Apple-tab-span" style="white-space:pre">        </span>-- Ian<br><br><br><br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></blockquote></div><br></div></div></div>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br></div></body></html>