<div dir="ltr">Hi,<div><br></div><div>I am working on integrating an OpenSAML IDP with Google&#39;s SP for Google Apps SSO. I&#39;m running into the following issue however: &quot;<b>Google Apps -- </b><span style="font-size:100%"><b>This account cannot be accessed because we could not parse the login request.</b>&quot;</span></div>
<div><span style="font-size:100%"><br></span></div><div>Has anyone run into the following issue? I&#39;ve run my authnresponse against various XML validators which don&#39;t report any errors.</div><div><br></div><div>I was also wondering how to send an unencrypted SAML Message. It looks like the OpenSAML SAMLMessageEncoder sends encrypted SAML responses by default. <b>How can I send an unencrypted SAML response?</b></div>
<div><br></div><div><b>Here&#39;s the AuthnResponse my OpenSAML IDP is Generating:</b></div><div><br></div><div><div>&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;&lt;saml2p:Response xmlns:saml2p=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot; Destination=&quot;<a href="https://www.google.com/a/mysite.com/acs">https://www.google.com/a/mysite.com/acs</a>&quot; ID=&quot;44859d3d-6e72-4ce1-ae2f-9c5420f1e29f&quot; InResponseTo=&quot;kmljhpobfepghlhlajipoodlenilbficclihpmfp&quot; IssueInstant=&quot;2013-09-03T20:56:43.462Z&quot; Version=&quot;2.0&quot; xmlns:xs=&quot;<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>&quot;&gt;</div>
<div>   &lt;saml2:Issuer xmlns:saml2=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot; Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:entity&quot;&gt;testrnsidptn&lt;/saml2:Issuer&gt;</div><div>   &lt;ds:Signature xmlns:ds=&quot;<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>&quot;&gt;</div>
<div>      &lt;ds:SignedInfo&gt;</div><div>         &lt;ds:CanonicalizationMethod Algorithm=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot;/&gt;</div><div>         &lt;ds:SignatureMethod Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>&quot;/&gt;</div>
<div>         &lt;ds:Reference URI=&quot;#44859d3d-6e72-4ce1-ae2f-9c5420f1e29f&quot;&gt;</div><div>            &lt;ds:Transforms&gt;</div><div>               &lt;ds:Transform Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>&quot;/&gt;</div>
<div>               &lt;ds:Transform Algorithm=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot;&gt;</div><div>                  &lt;ec:InclusiveNamespaces xmlns:ec=&quot;<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>&quot; PrefixList=&quot;xs&quot;/&gt;</div>
<div>               &lt;/ds:Transform&gt;</div><div>            &lt;/ds:Transforms&gt;</div><div>            &lt;ds:DigestMethod Algorithm=&quot;<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>&quot;/&gt;</div>
<div>            &lt;ds:DigestValue&gt;6SUQDg+IsAsdGPGb1l2zbHEE6Es=&lt;/ds:DigestValue&gt;</div><div>         &lt;/ds:Reference&gt;</div><div>      &lt;/ds:SignedInfo&gt;</div><div>      &lt;ds:SignatureValue&gt;FH5LcHVerraDormvl1guXthfrQZuseJPQeLhDEf1lsak1nu0/HShhYRCsN3JxwPRDNIeyrAcxzTztMkWLwXTG2D1uuDYFJHVKkxO9dkXDSYh1kc6aL7U95yML2nBWQBP2ffG4PbZ3xWJ0Ic4Km10wMAhyBCCPHQb7QPn2fBMpMckf77SJCh73L3v3eaM/cGQJGiOujGQorLcSAfvqIc8nx1fwM5H+k0oW+itRLRRlEVJ60b7xfYHXFM45U6S4sIhRF+K5dx8UfGguVkyCzDcHtzdkZyfYvrOvrzx0EE3hqcDR7PgCOsZ6yhSDNTnYtB62eoFxX80rojM7cte+L9UnQ==&lt;/ds:SignatureValue&gt;</div>
<div>      &lt;ds:KeyInfo&gt;</div><div>         &lt;ds:X509Data&gt;</div><div>            &lt;ds:X509Certificate&gt;MIIDejCCAmKgAwIBAgIEUgv21TANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJVUzETMBEGA1UE</div><div>CBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNU2FuIEZyYW5jaXNjbzEbMBkGA1UEChMSUmVzaWxpZW50</div>
<div>IE5ldHdvcmtzMQ8wDQYDVQQLEwZEZXZvcHMxFTATBgNVBAMTDFNsb2FuIExvb25leTAeFw0xMzA4</div><div>MTQyMTI5NTdaFw0xNDA4MTQyMTI5NTdaMH8xCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9y</div><div>bmlhMRYwFAYDVQQHEw1TYW4gRnJhbmNpc2NvMRswGQYDVQQKExJSZXNpbGllbnQgTmV0d29ya3Mx</div>
<div>DzANBgNVBAsTBkRldm9wczEVMBMGA1UEAxMMU2xvYW4gTG9vbmV5MIIBIjANBgkqhkiG9w0BAQEF</div><div>AAOCAQ8AMIIBCgKCAQEAnqLAiMgGWk3GUgEy2rvZiOfvpVvsIR946FCBwPKHPKeDpK3dO3vcVg+S</div><div>P5lbGijOPIsBy8oS8RnOalU+f4W1TF8PjiOhgpH0FDcM6Sl/LWFTMS3PHbU5E/TuhfAoFM7/5JvJ</div>
<div>Y2ncSd6jrJepYS9FdGE+V6PIAZ/tGexFZYDIaVhJecH0fy/rFYAOn4kb3yETSCju0sdvY9ieye1+</div><div>kp/ZM2uiXutO3VsAq2OMRyy/C9lmqxfsYMwzoZ0iqQ4mTK/imPVukXzw65e+IjMi7oz/McMiyECr</div><div>cPf0d//Zqrb6NF8wlsh2O5uRMAgJn+Hm3hEnM9FxIKHIhWoIggF21cgUPwIDAQABMA0GCSqGSIb3</div>
<div>DQEBBQUAA4IBAQASni6M0jdk4I3QUKHBdD/W/1Y2v9m21SgKuj8kg4qNTT8tmIGLtHK3F8bVy61E</div><div>0DGpIUyfq8ZXfE16szvT6U8cEHC6sA/hyWuwf6guu+4Y7Xr/DEFO7zBtSDLkFr9llsNCSp/QkBkg</div><div>DeE0AYFfx95k7KBuk6OUKUodQ7VIMyOIeE8qYXqBnHQU+1hrXeGQ1Qf5fe62q2IivZEoKALZPR9e</div>
<div>mDeAYjxEagIfizy01fr8rbWW0apjOX3xCkF35qDWNQLRS8ZViuhqd+mS2hrZzCy3IKs/Un4xR8oz</div><div>035qvpwWk8gDK1fEuK2cazRJfSDanWLGA620xY13fShNG4dBw79E&lt;/ds:X509Certificate&gt;</div><div>         &lt;/ds:X509Data&gt;</div><div>
      &lt;/ds:KeyInfo&gt;</div><div>   &lt;/ds:Signature&gt;</div><div>   &lt;saml2p:Status&gt;</div><div>      &lt;saml2p:StatusCode Value=&quot;urn:oasis:names:tc:SAML:2.0:status:Success&quot;/&gt;</div><div>   &lt;/saml2p:Status&gt;</div>
<div>   &lt;saml2:Assertion xmlns:saml2=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot; ID=&quot;47b0b83f-3a77-4ed3-877f-37957cd0c710&quot; IssueInstant=&quot;2013-09-03T20:56:43.461Z&quot; Version=&quot;2.0&quot;&gt;</div>
<div>      &lt;saml2:Issuer Format=&quot;urn:oasis:names:tc:SAML:2.0:nameid-format:entity&quot;&gt;testrnsidptn&lt;/saml2:Issuer&gt;</div><div>      &lt;saml2:Subject&gt;</div><div>         &lt;saml2:NameID Format=&quot;urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified&quot;&gt;<a href="mailto:sptester@mysite.com">sptester@mysite.com</a>&lt;/saml2:NameID&gt;</div>
<div>         &lt;saml2:SubjectConfirmation Method=&quot;urn:oasis:names:tc:SAML:2.0:cm:bearer&quot;&gt;</div><div>            &lt;saml2:SubjectConfirmationData Address=&quot;199.188.194.207&quot; InResponseTo=&quot;kmljhpobfepghlhlajipoodlenilbficclihpmfp&quot; NotOnOrAfter=&quot;2013-09-03T20:58:13.444Z&quot; Recipient=&quot;<a href="https://www.google.com/a/mysite.com/acs">https://www.google.com/a/mysite.com/acs</a>&quot;/&gt;</div>
<div>         &lt;/saml2:SubjectConfirmation&gt;</div><div>      &lt;/saml2:Subject&gt;</div><div>      &lt;saml2:AuthnStatement AuthnInstant=&quot;2013-09-03T20:56:16.961Z&quot;&gt;</div><div>         &lt;saml2:AuthnContext&gt;</div>
<div>            &lt;saml2:AuthnContextClassRef&gt;urn:oasis:names:tc:SAML:2.0:ac:classes:Password&lt;/saml2:AuthnContextClassRef&gt;</div><div>         &lt;/saml2:AuthnContext&gt;</div><div>      &lt;/saml2:AuthnStatement&gt;</div>
<div>      &lt;saml2:AttributeStatement&gt;</div><div>         &lt;saml2:Attribute FriendlyName=&quot;uid&quot; Name=&quot;uid&quot; NameFormat=&quot;urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified&quot;&gt;</div>
<div>            &lt;saml2:AttributeValue xmlns:xsi=&quot;<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>&quot; xsi:type=&quot;xs:string&quot;&gt;<a href="mailto:sptester@mysite.com">sptester@mysite.com</a>&lt;/saml2:AttributeValue&gt;</div>
<div>         &lt;/saml2:Attribute&gt;</div><div>      &lt;/saml2:AttributeStatement&gt;</div><div>   &lt;/saml2:Assertion&gt;</div><div>&lt;/saml2p:Response&gt;</div></div><div><br></div><div><br></div><div>Thanks,</div>
<div><br></div><div>Rohit</div></div>