<div dir="ltr">Hi (and thanks for the reply Scott),<br><div><div class="gmail_extra"><br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">


Is it clustered?<br></blockquote><div><br></div><div>Yes, two servers behind a load balancer.<br></div><br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div>

</div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPCookieUsage" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPCookieUsage</a><br>
<br>
Unless you have a non-sticky cluster, your browser isn&#39;t sending back the<br>
appropriate cookie during the process.<br>
</blockquote><div><br></div><div>Thanks for the link. You might be on to something, but it seems odd that the browser would have an issue with one particular SP but not others. Or am I misunderstanding?<br></div><div> </div>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">It&#39;s your end, unless they are sending the request to the wrong endpoint.<br>
That seems a likely possibility.<br></blockquote><div><br></div><div>I will verify with the vendor what they put in as the endpoint. Can I check that on my end? Using firebug and going to their URL and watching where I&#39;m sent, it looks like I&#39;m ending up going to /idp/profile/Shibboleth/SSO on my Shibboleth IdP server. Using a different SP (that works) it seems to go to /idp/profile/SAML2/Redirect/SSO. Not sure if that&#39;s relevant or not.<br>
<br></div><div>Any other guidance would be much appreciated. <br><br></div><div>Thanks again for the response,<br>Ian<br></div></div></div></div></div>