<div dir="ltr"><div><div><div>Hi again,<br><blockquote>&quot;Error decoding Shibboleth SSO request&quot; and the profile URL above means they are /not/ using SAML2 like they claimed, but the lagacy &quot;Shibboleth profile&quot; (plus extensions) of SAML1.1,<br>
</blockquote><br></div>I wrote to this SP vendor again and they claim &quot;We are using SAML 2.0 with the HTTP-Redirect protocol. The metadata file indicates the /idp/profile/SAML2/Redirect/SSO as the endpoint.&quot;<br>
<br></div>I think they are referring to the location attribute on the <i>SingleSignOnService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect&quot; </i>element in my metadata file.<br><br></div>Is there something wrong in my metadata file? Is the SP vendor reading the metadata document incorrectly? Other?<br>
<br>Thanks again for your assistance.<br><br>Ian<br></div>