<div dir="ltr">Hi,<br><div class="gmail_extra"><div class="gmail_quote"><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
Is the SP signing the AuthnRequest? If so, the Destination XML<br>
attribute is required.</blockquote><div><br></div><div>I&#39;m not sure how to determine if it&#39;s signed, but I imagine it is given the error. Watching my IdP logs with SPs 
that work, I see that some say  &quot;SAML message intended destination endpoint in message was empty, not 
required by binding, skipping&quot; while others tell me the &quot;SAML message 
intended destination endpoint matched recipient endpoint.&quot;
</div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Alternatively, then can stop signing the
request, especially if you have trusted metadata for the SP.<br></blockquote><div><br></div></div>Ah, that&#39;s a good point. I will mention that to the SP vendor.<br></div><div class="gmail_extra"><br><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">

That said, I wrote that wikipedia entry, and if it&#39;s wrong, I will fix it.<br></blockquote>
<br><div class=""><div id=":498" class="" tabindex="0"><img class="" src="https://mail.google.com/mail/u/0/images/cleardot.gif">Hopefully Scot can chime in, but now that I read the up on the destination attribute in the standards document I think it&#39;s not that the wikipedia entry is wrong, but that it doesn&#39;t mention destination attribute is required if it&#39;s signed. Or perhaps just note something like that the example is an example request and not meant to be the standard for all requests?<br>
</div></div></div><div class="gmail_extra"><br></div><div class="gmail_extra">Thanks,<br></div><div class="gmail_extra">Ian<br></div></div>