<div dir="ltr">Hi,<div><br></div><div>I am working on integrating an OpenSAML IDP with Google's SP for Google Apps SSO. I'm running into the following issue however: "<b>Google Apps -- </b><span style="font-size:100%"><b>This account cannot be accessed because we could not parse the login request.</b>"</span></div>
<div><span style="font-size:100%"><br></span></div><div>Has anyone run into the following issue? I've run my authnresponse against various XML validators which don't report any errors.</div><div><br></div><div>I was also wondering how to send an unencrypted SAML Message. It looks like the OpenSAML SAMLMessageEncoder sends encrypted SAML responses by default. <b>How can I send an unencrypted SAML response?</b></div>
<div><br></div><div><b>Here's the AuthnResponse my OpenSAML IDP is Generating:</b></div><div><br></div><div><div><?xml version="1.0" encoding="UTF-8"?><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="<a href="https://www.google.com/a/mysite.com/acs">https://www.google.com/a/mysite.com/acs</a>" ID="44859d3d-6e72-4ce1-ae2f-9c5420f1e29f" InResponseTo="kmljhpobfepghlhlajipoodlenilbficclihpmfp" IssueInstant="2013-09-03T20:56:43.462Z" Version="2.0" xmlns:xs="<a href="http://www.w3.org/2001/XMLSchema">http://www.w3.org/2001/XMLSchema</a>"></div>
<div> <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">testrnsidptn</saml2:Issuer></div><div> <ds:Signature xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"></div>
<div> <ds:SignedInfo></div><div> <ds:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/></div><div> <ds:SignatureMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#rsa-sha1">http://www.w3.org/2000/09/xmldsig#rsa-sha1</a>"/></div>
<div> <ds:Reference URI="#44859d3d-6e72-4ce1-ae2f-9c5420f1e29f"></div><div> <ds:Transforms></div><div> <ds:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/></div>
<div> <ds:Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"></div><div> <ec:InclusiveNamespaces xmlns:ec="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>" PrefixList="xs"/></div>
<div> </ds:Transform></div><div> </ds:Transforms></div><div> <ds:DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>"/></div>
<div> <ds:DigestValue>6SUQDg+IsAsdGPGb1l2zbHEE6Es=</ds:DigestValue></div><div> </ds:Reference></div><div> </ds:SignedInfo></div><div> <ds:SignatureValue>FH5LcHVerraDormvl1guXthfrQZuseJPQeLhDEf1lsak1nu0/HShhYRCsN3JxwPRDNIeyrAcxzTztMkWLwXTG2D1uuDYFJHVKkxO9dkXDSYh1kc6aL7U95yML2nBWQBP2ffG4PbZ3xWJ0Ic4Km10wMAhyBCCPHQb7QPn2fBMpMckf77SJCh73L3v3eaM/cGQJGiOujGQorLcSAfvqIc8nx1fwM5H+k0oW+itRLRRlEVJ60b7xfYHXFM45U6S4sIhRF+K5dx8UfGguVkyCzDcHtzdkZyfYvrOvrzx0EE3hqcDR7PgCOsZ6yhSDNTnYtB62eoFxX80rojM7cte+L9UnQ==</ds:SignatureValue></div>
<div> <ds:KeyInfo></div><div> <ds:X509Data></div><div> <ds:X509Certificate>MIIDejCCAmKgAwIBAgIEUgv21TANBgkqhkiG9w0BAQUFADB/MQswCQYDVQQGEwJVUzETMBEGA1UE</div><div>CBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNU2FuIEZyYW5jaXNjbzEbMBkGA1UEChMSUmVzaWxpZW50</div>
<div>IE5ldHdvcmtzMQ8wDQYDVQQLEwZEZXZvcHMxFTATBgNVBAMTDFNsb2FuIExvb25leTAeFw0xMzA4</div><div>MTQyMTI5NTdaFw0xNDA4MTQyMTI5NTdaMH8xCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9y</div><div>bmlhMRYwFAYDVQQHEw1TYW4gRnJhbmNpc2NvMRswGQYDVQQKExJSZXNpbGllbnQgTmV0d29ya3Mx</div>
<div>DzANBgNVBAsTBkRldm9wczEVMBMGA1UEAxMMU2xvYW4gTG9vbmV5MIIBIjANBgkqhkiG9w0BAQEF</div><div>AAOCAQ8AMIIBCgKCAQEAnqLAiMgGWk3GUgEy2rvZiOfvpVvsIR946FCBwPKHPKeDpK3dO3vcVg+S</div><div>P5lbGijOPIsBy8oS8RnOalU+f4W1TF8PjiOhgpH0FDcM6Sl/LWFTMS3PHbU5E/TuhfAoFM7/5JvJ</div>
<div>Y2ncSd6jrJepYS9FdGE+V6PIAZ/tGexFZYDIaVhJecH0fy/rFYAOn4kb3yETSCju0sdvY9ieye1+</div><div>kp/ZM2uiXutO3VsAq2OMRyy/C9lmqxfsYMwzoZ0iqQ4mTK/imPVukXzw65e+IjMi7oz/McMiyECr</div><div>cPf0d//Zqrb6NF8wlsh2O5uRMAgJn+Hm3hEnM9FxIKHIhWoIggF21cgUPwIDAQABMA0GCSqGSIb3</div>
<div>DQEBBQUAA4IBAQASni6M0jdk4I3QUKHBdD/W/1Y2v9m21SgKuj8kg4qNTT8tmIGLtHK3F8bVy61E</div><div>0DGpIUyfq8ZXfE16szvT6U8cEHC6sA/hyWuwf6guu+4Y7Xr/DEFO7zBtSDLkFr9llsNCSp/QkBkg</div><div>DeE0AYFfx95k7KBuk6OUKUodQ7VIMyOIeE8qYXqBnHQU+1hrXeGQ1Qf5fe62q2IivZEoKALZPR9e</div>
<div>mDeAYjxEagIfizy01fr8rbWW0apjOX3xCkF35qDWNQLRS8ZViuhqd+mS2hrZzCy3IKs/Un4xR8oz</div><div>035qvpwWk8gDK1fEuK2cazRJfSDanWLGA620xY13fShNG4dBw79E</ds:X509Certificate></div><div> </ds:X509Data></div><div>
</ds:KeyInfo></div><div> </ds:Signature></div><div> <saml2p:Status></div><div> <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></div><div> </saml2p:Status></div>
<div> <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="47b0b83f-3a77-4ed3-877f-37957cd0c710" IssueInstant="2013-09-03T20:56:43.461Z" Version="2.0"></div>
<div> <saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">testrnsidptn</saml2:Issuer></div><div> <saml2:Subject></div><div> <saml2:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"><a href="mailto:sptester@mysite.com">sptester@mysite.com</a></saml2:NameID></div>
<div> <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"></div><div> <saml2:SubjectConfirmationData Address="199.188.194.207" InResponseTo="kmljhpobfepghlhlajipoodlenilbficclihpmfp" NotOnOrAfter="2013-09-03T20:58:13.444Z" Recipient="<a href="https://www.google.com/a/mysite.com/acs">https://www.google.com/a/mysite.com/acs</a>"/></div>
<div> </saml2:SubjectConfirmation></div><div> </saml2:Subject></div><div> <saml2:AuthnStatement AuthnInstant="2013-09-03T20:56:16.961Z"></div><div> <saml2:AuthnContext></div>
<div> <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:Password</saml2:AuthnContextClassRef></div><div> </saml2:AuthnContext></div><div> </saml2:AuthnStatement></div>
<div> <saml2:AttributeStatement></div><div> <saml2:Attribute FriendlyName="uid" Name="uid" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified"></div>
<div> <saml2:AttributeValue xmlns:xsi="<a href="http://www.w3.org/2001/XMLSchema-instance">http://www.w3.org/2001/XMLSchema-instance</a>" xsi:type="xs:string"><a href="mailto:sptester@mysite.com">sptester@mysite.com</a></saml2:AttributeValue></div>
<div> </saml2:Attribute></div><div> </saml2:AttributeStatement></div><div> </saml2:Assertion></div><div></saml2p:Response></div></div><div><br></div><div><br></div><div>Thanks,</div>
<div><br></div><div>Rohit</div></div>