<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Before I confuse everyone, here is the actual AuthnRequest sent by SugarCRM…<div><br></div><div><div>&lt;samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" ID="_89a3b55aa73d637c4978" Version="2.0" IssueInstant="2013-02-07T11:48:48Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" AssertionConsumerServiceURL="<a href="https://trial.sugarcrm.com/rvufhi7392/index.php?module=Users&amp;action=Authenticate">https://trial.sugarcrm.com/rvufhi7392/index.php?module=Users&amp;action=Authenticate</a>"&gt;&lt;saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"&gt;php-saml&lt;/saml:Issuer&gt;</div><div>&lt;samlp:NameIDPolicy xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" AllowCreate="true"&gt;&lt;/samlp:NameIDPolicy&gt;</div><div>&lt;samlp:RequestedAuthnContext xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" Comparison="exact"&gt;&lt;saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport&lt;/saml:AuthnContextClassRef&gt;&lt;/samlp:RequestedAuthnContext&gt;</div><div>&lt;/samlp:AuthnRequest&gt;</div><div><br></div><div>Apologies</div><div>Glenn</div><div apple-content-edited="true">
<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><div><a href="http://www.edugate.ie">Edugate</a>&nbsp;Operations</div><div><a href="http://www.heanet.ie">HEAnet Limited</a>, Ireland's Education and Research Network -&nbsp;</div><div>1st Floor, 5 George's Dock, IFSC, Dublin 1</div><div>Registered in Ireland, no 275301 &nbsp;tel: +353-1-6609040 &nbsp;fax: +353-1-6603666</div></div></div>
</div>
<br><div><div>On 7 Feb 2013, at 11:35, Glenn Wearen wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">The character before the 'action' was indeed an ampersand, and this is rejected by the IdP. When I urlencode it manually (using the&nbsp;<a href="https://rnd.feide.no/simplesaml/module.php/saml2debug/debug.php">Feide SAML debugger</a>) the IdP parses it.<div>Thanks</div><div>Glenn<br><div><br></div><div><br><div>Edugate&nbsp;Operations<br>HEAnet Limited, Ireland's Education and Research Network -&nbsp;<br>1st Floor, 5 George's Dock, IFSC, Dublin 1<br>Registered in Ireland, no 275301 &nbsp;tel: +353-1-6609040 &nbsp;fax: +353-1-6603666<br></div><br><div><div>On 7 Feb 2013, at 10:31, Ian Young wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div><br>On 7 Feb 2013, at 09:54, Glenn Wearen &lt;<a href="mailto:glenn.wearen@heanet.ie">glenn.wearen@heanet.ie</a>&gt; wrote:<br><br><blockquote type="cite">Slight correction, it is the ampersand that I have urlencoded, not the question mark.<br></blockquote><br>The example you posted doesn't contain an ampersand. &nbsp;If the character before the "action" was an ampersand, that would be invalid XML, which is what the IdP is reporting.<br><br>As to whether the "right" answer is for the SP to URL encode such an ampersand as %25 within the XML, in the hope that it won't be decoded prior to being used in a URL, I'm not sure. &nbsp;I have seen that done, but if you don't have control over what the SP is generating then that may be moot.<br><br>There was a change in behaviour in this area in the IdP at some point in the 2.X series. &nbsp;I want to say something like 2.2.0, but I can't see the specific issue in the release notes; it may have been a side-effect of fixing something else and perhaps someone else can remember the details. &nbsp;We've also had related issues in the discovery service code. &nbsp;I do remember that we were fairly confident that the IdP was doing the right thing now, though.<br><br><span class="Apple-tab-span" style="white-space:pre">        </span>-- Ian<br><br><br><br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></blockquote></div><br></div></div></div>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br></div></body></html>